Exam 17: Digital Evidence on Windows Systems

arrow
  • Select Tags
search iconSearch Question
  • Select Tags

EnCase can recover deleted files but does not have the capability of recovering deleted directories.

Free
(True/False)
4.8/5
(31)
Correct Answer:
Verified

False

Internet traces may be found in which of the following categories?

Free
(Multiple Choice)
4.7/5
(35)
Correct Answer:
Verified

D

With the correct CMOS setting, it is possible to mount a hard drive as Read-Only in the Windows environment.

Free
(True/False)
4.9/5
(37)
Correct Answer:
Verified

False

Before evidentiary media is "acquired," forensic examiners often______________ the media to make sure it contains data relevant to the investigation.

(Multiple Choice)
5.0/5
(32)

Log files are used by the forensic examiner to_________ .

(Multiple Choice)
4.9/5
(30)

When examining the "news.rc," you find the following entry:  alt.binaries.hacking.utilities! 18905,8912,8921,8924,8926,8929,8930,8932\text { alt.binaries.hacking.utilities! } 1 - 8905,8912,8921,8924,8926,8929,8930,8932 What does the "!" mean?

(Multiple Choice)
4.7/5
(22)

NTFS time represents time as the number of 100-nanosecond intervals since January 1, 1601 00:00:00 UTC.

(True/False)
4.8/5
(29)

In NTFS, when a file is deleted from a directory, the last modified and accessed date-time stamps of the parent directory listing are updated.

(True/False)
4.8/5
(33)

In FAT32 file systems both the directory and FAT entries are updated when a file is deleted.

(True/False)
4.8/5
(34)

The standard Windows environment supports all of the following file systems EXCEPT____________ .

(Multiple Choice)
4.7/5
(34)

"File carving" is an examination technique where the beginning and end of a file are located, and the block of data spanning the two locations is copied to a new file, with the appropriate extension.

(True/False)
4.7/5
(33)

When a file is moved within a volume, the Last Accessed Date Time:

(Multiple Choice)
5.0/5
(36)

In the Windows environment, simply opening a file to read, without writing it back to disk, can change the date-time stamp.

(True/False)
4.9/5
(34)

The Windows environment is invasive and poses a challenge to forensic examiners.

(True/False)
4.9/5
(29)

Forensically acceptable alternatives to using a Windows Evidence Acquisition Boot Disk include all but which of the following?

(Multiple Choice)
4.8/5
(34)

Usenet readers store all the URLs that have been accessed, but do not record which Usenet newsgroups have been accessed and joined.

(True/False)
4.7/5
(28)

6 . Which of the following software tools is NOT used for data recovery?

(Multiple Choice)
4.8/5
(28)

Media can be accessed for examination either ________or____________ . (Choose two)

(Multiple Choice)
4.9/5
(28)

Windows evidentiary media must be acquired and examined with Windows-based examination software.

(True/False)
4.9/5
(37)

Given their widespread use and simple structure, FAT file systems are a good starting point for forensic analysts to understand file systems and recovery of deleted data.

(True/False)
4.9/5
(33)
Showing 1 - 20 of 30
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)