When can an evidence file containing a NTFS partition be logically restored to a FAT 32 partition?
The EnCase methodology dictates that the lab drive for evidence have a __________ prior to making an image.
All investigators using EnCase should run tests on the evidence file acquisition and verification process to:
To undelete a file in the FAT file system, EnCase obtains the starting extent from the:
A signature analysis has been run on a case. The result "Bad Signature " means:
EnCase marks a file as overwritten when _____________ has been allocated to another file.
This question addresses the EnCase for Windows search process. If a target word is within a logical file, and it begins in cluster 10 and ends in cluster 15 (the word is fragmented), the search:
The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. Jan 1st, 2?0?00
If cases are worked on a lab drive in a secure room, without any cleaning of the contents of the drive, which of the following areas would be of most concern?
Select the appropriate name for the highlighted area of the binary numbers.
An evidence file was archived onto five CD-Rom disks with the third file segment on disk number three. Can the contents of the third file segment be verified by itself while still on the CD?
Select the appropriate name for the highlighted area of the binary numbers.
Two allocated files can occupy one cluster, as long as they can both fit within the allotted number of bytes.
What information should be obtained from the BIOS during computer forensic investigations?