Exam 17: Digital Evidence on Windows Systems
Exam 1: Foundations of Digital Forensics 36 Questions
Exam 2: Language of Computer Crime Investigation33 Questions
Exam 3: Digital Evidence in the Courtroom29 Questions
Exam 4: Cybercrime Law: a United States Perspective30 Questions
Exam 5: Cybercrime Law: a European Perspective30 Questions
Exam 6: Conducting Digital Investigations33 Questions
Exam 7: Handling a Digital Crime Scene32 Questions
Exam 8: Investigative Reconstruction With Digital Evidence32 Questions
Exam 9: Modus Operandi, Motive, and Technology32 Questions
Exam 10: Violent Crime and Digital Evidence30 Questions
Exam 11: Digital Evidence As Alibi18 Questions
Exam 12: Sex Offenders on the Internet31 Questions
Exam 13: Computer Intrusions32 Questions
Exam 14: Cyberstalking31 Questions
Exam 15: Computer Basics for Digital Investigators34 Questions
Exam 16: Applying Forensic Science to Computers31 Questions
Exam 17: Digital Evidence on Windows Systems30 Questions
Exam 18: Digital Evidence on Unix Systems30 Questions
Exam 19: Digital Evidence on Macintosh Systems29 Questions
Exam 20: Digital Evidence on Mobile Devices32 Questions
Exam 21: Network Basics for Digital Investigators33 Questions
Exam 22: Applying Forensic Science to Networks35 Questions
Exam 23: Digital Evidence on the Internet30 Questions
Exam 24: Digital Evidence at the Physical and Data-Link Layers34 Questions
Exam 25: Digital Evidence at the Network and Transport Layers30 Questions
Select questions type
EnCase can recover deleted files but does not have the capability of recovering deleted directories.
Free
(True/False)
4.8/5
(31)
Correct Answer:
False
Internet traces may be found in which of the following categories?
Free
(Multiple Choice)
4.7/5
(35)
Correct Answer:
D
With the correct CMOS setting, it is possible to mount a hard drive as Read-Only in the Windows environment.
Free
(True/False)
4.9/5
(37)
Correct Answer:
False
Before evidentiary media is "acquired," forensic examiners often______________ the media to make sure it contains data relevant to the investigation.
(Multiple Choice)
5.0/5
(32)
When examining the "news.rc," you find the following entry:
What does the "!" mean?
(Multiple Choice)
4.7/5
(22)
NTFS time represents time as the number of 100-nanosecond intervals since January 1, 1601 00:00:00 UTC.
(True/False)
4.8/5
(29)
In NTFS, when a file is deleted from a directory, the last modified and accessed date-time stamps of the parent directory listing are updated.
(True/False)
4.8/5
(33)
In FAT32 file systems both the directory and FAT entries are updated when a file is deleted.
(True/False)
4.8/5
(34)
The standard Windows environment supports all of the following file systems EXCEPT____________ .
(Multiple Choice)
4.7/5
(34)
"File carving" is an examination technique where the beginning and end of a file are located, and the block of data spanning the two locations is copied to a new file, with the appropriate extension.
(True/False)
4.7/5
(33)
When a file is moved within a volume, the Last Accessed Date Time:
(Multiple Choice)
5.0/5
(36)
In the Windows environment, simply opening a file to read, without writing it back to disk, can change the date-time stamp.
(True/False)
4.9/5
(34)
The Windows environment is invasive and poses a challenge to forensic examiners.
(True/False)
4.9/5
(29)
Forensically acceptable alternatives to using a Windows Evidence Acquisition Boot Disk include all but which of the following?
(Multiple Choice)
4.8/5
(34)
Usenet readers store all the URLs that have been accessed, but do not record which Usenet newsgroups have been accessed and joined.
(True/False)
4.7/5
(28)
6 . Which of the following software tools is NOT used for data recovery?
(Multiple Choice)
4.8/5
(28)
Media can be accessed for examination either ________or____________ . (Choose two)
(Multiple Choice)
4.9/5
(28)
Windows evidentiary media must be acquired and examined with Windows-based examination software.
(True/False)
4.9/5
(37)
Given their widespread use and simple structure, FAT file systems are a good starting point for forensic analysts to understand file systems and recovery of deleted data.
(True/False)
4.9/5
(33)
Showing 1 - 20 of 30
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)