Easter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Certification Exam for EnCE Outside North America Question and Answers

Certification Exam for EnCE Outside North America

Last Update May 18, 2024
Total Questions : 174

We are offering FREE GD0-110 Guidance Software exam questions. All you do is to just go and sign up. Give your details, prepare GD0-110 free exam questions and then go for complete pool of Certification Exam for EnCE Outside North America test questions that will help you more.

GD0-110 pdf

GD0-110 PDF

$35  $99.99
GD0-110 Engine

GD0-110 Testing Engine

$42  $119.99
GD0-110 PDF + Engine

GD0-110 PDF + Testing Engine

$56  $159.99
Questions 1

When a file is deleted in the FAT file system, what happens to the FAT?

Options:

A.  

It is deleted as well.

B.  

Nothing.

C.  

The FAT entries for that file are marked as allocated.

D.  

The FAT entries for that file are marked as available.

Discussion 0
Questions 2

A standard DOS 6.22 boot disk is acceptable for booting a suspect drive.

Options:

A.  

True

B.  

False

Discussion 0
Questions 3

You are at an incident scene and determine that a computer contains evidence as described in the search warrant. When you seize the computer, you should:

Options:

A.  

Record the location that the computer was recovered from.

B.  

Record the identity of the person(s) involved in the seizure.

C.  

Record the date and time the computer was seized.

D.  

Record nothing to avoid inaccuracies that might jeopardize the use of the evidence.

Discussion 0
Questions 4

A CPU is:

Options:

A.  

An entire computer box, not including the monitor and other attached peripheral devices.

B.  

A motherboard with all required devices connected.

C.  

A Central Programming Unit.

D.  

A chip that would be considered the brain of a computer, which is installed on a motherboard.

Discussion 0
Questions 5

The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. 800[) \-]+555-1212

Options:

A.  

800.555.1212

B.  

8005551212

C.  

800-555 1212

D.  

(800) 555-1212

Discussion 0
Questions 6

During the power-up sequence, which of the following happens first?

Options:

A.  

The boot sector is located on the hard drive.

B.  

The power On Self-Test.

C.  

The floppy drive is checked for a diskette.

D.  

The BIOS on an add-in card is executed.

Discussion 0
Questions 7

Which of the following selections would be used to keep track of a fragmented file in the FAT file system?

Options:

A.  

The File Allocation Table

B.  

The directory entry for the fragmented file

C.  

The partition table of extents

D.  

All of the above

Discussion 0
Questions 8

Within EnCase, clicking on save on the toolbar affects what file(s)?

Options:

A.  

The open case file

B.  

The configuration .ini files

C.  

The evidence files

D.  

All of the above

Discussion 0
Questions 9

EnCase can build a hash set of a selected group of files.

Options:

A.  

True

B.  

False

Discussion 0
Questions 10

What are the EnCase configuration .ini files used for?

Options:

A.  

Storing information that is specific to a particular case.

B.  

Storing information that will be available to EnCase each time it is opened, regardless of the active case(s).

C.  

Storing pointers to acquired evidence.

D.  

Storing the results of a signature analysis.

Discussion 0
Questions 11

In Windows 2000 and XP, which of the following directories contain user personal folders?

Options:

A.  

C:\Windows\Users

B.  

C:\Personnel Folders

C.  

C:\Documents and Settings

D.  

C:\WINNT\Profiles

Discussion 0
Questions 12

The MD5 hash algorithm produces a _____ number.

Options:

A.  

32 bit

B.  

64 bit

C.  

128 bit

D.  

256 bit

Discussion 0
Questions 13

The FAT in the File Allocation Table file system keeps track of:

Options:

A.  

File fragmentation

B.  

Every addressable cluster on the partition

C.  

Clusters marked as bad

D.  

All of the above.

Discussion 0
Questions 14

A case file can contain ____ hard drive images?

Options:

A.  

1

B.  

5

C.  

10

D.  

any number of

Discussion 0
Questions 15

An evidence file was archived onto five CD-Rom disks with the third file segment on disk number three. Can the contents of the third file segment be verified by itself while still on the CD?

Options:

A.  

No. All file segments must be put back together.

B.  

Yes. Any segment of an evidence file can be verified through re-computing and comparing the CRCs, even if it is on a CD.

C.  

No. EnCase cannot verify files on CDs.

D.  

No. Archived files are compressed and cannot be verified until un-archived.

Discussion 0
Questions 16

A standard Windows 98 boot disk is acceptable for booting a suspect drive.

Options:

A.  

True

B.  

False

Discussion 0
Questions 17

Temp files created by EnCase are deleted when EnCase is properly closed.

Options:

A.  

True

B.  

False

Discussion 0
Questions 18

The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. [^a-z]Tom[^a-z]

Options:

A.  

Stomp

B.  

Tomato

C.  

Tom

D.  

Toms

Discussion 0
Questions 19

A hard drive has been formatted as NTFS and Windows XP was installed. The user used fdisk to remove all partitions from that drive. Nothing else was done. You have imaged the drive and have opened the evidence file with EnCase. What would be the best way to examine this hard drive?

Options:

A.  

Conduct a physical search of the hard drive and bookmark any evidence.

B.  

Use the add Partition feature to rebuild the partition and then examine the system.

C.  

Use the recovered Deleted Partitions feature and then examine the system.

D.  

EnCase will not see a drive that has been fdisked.

Discussion 0
Questions 20

The following keyword was typed in exactly as shown. Choose the answer(s) that would result. All search criteria have default settings. credit card

Options:

A.  

Credit

B.  

Card

C.  

Credit Card

D.  

credit card

Discussion 0
Questions 21

What information should be obtained from the BIOS during computer forensic investigations?

Options:

A.  

The video caching information

B.  

The port assigned to the serial port

C.  

The date and time

D.  

The boot sequence

Discussion 0
Questions 22

The EnCase default export folder is:

Options:

A.  

A global setting that can be changed.

B.  

A case-specific setting that can be changed.

C.  

A global setting that cannot be changed.

D.  

A case-specific setting that cannot be changed.

Discussion 0
Questions 23

If cluster number 10 in the FAT contains the number 55, this means:

Options:

A.  

That there is a cross-linked file.

B.  

That cluster 10 is used and the file continues in cluster number 55.

C.  

The cluster number 55 is the end of an allocated file.

D.  

That the file starts in cluster number 55 and continues to cluster number 10.

Discussion 0
Questions 24

Bookmarks are stored in which of the following files?

Options:

A.  

The case file

B.  

The configuration Bookmarks.ini file

C.  

The evidence file

D.  

All of the above

Discussion 0
Questions 25

A hash set would most accurately be described as:

Options:

A.  

A group of hash libraries organized by category.

B.  

A table of file headers and extensions.

C.  

A group of hash values that can be added to the hash library.

D.  

Both a and b.

Discussion 0
Questions 26

The maximum file segment size for an EnCase evidence file is:

Options:

A.  

500 MB

B.  

1000 MB

C.  

1500 MB

D.  

2000 MB

E.  

There is no limit.

Discussion 0