Exam 17: Digital Evidence on Windows Systems
Exam 1: Foundations of Digital Forensics 36 Questions
Exam 2: Language of Computer Crime Investigation33 Questions
Exam 3: Digital Evidence in the Courtroom29 Questions
Exam 4: Cybercrime Law: a United States Perspective30 Questions
Exam 5: Cybercrime Law: a European Perspective30 Questions
Exam 6: Conducting Digital Investigations33 Questions
Exam 7: Handling a Digital Crime Scene32 Questions
Exam 8: Investigative Reconstruction With Digital Evidence32 Questions
Exam 9: Modus Operandi, Motive, and Technology32 Questions
Exam 10: Violent Crime and Digital Evidence30 Questions
Exam 11: Digital Evidence As Alibi18 Questions
Exam 12: Sex Offenders on the Internet31 Questions
Exam 13: Computer Intrusions32 Questions
Exam 14: Cyberstalking31 Questions
Exam 15: Computer Basics for Digital Investigators34 Questions
Exam 16: Applying Forensic Science to Computers31 Questions
Exam 17: Digital Evidence on Windows Systems30 Questions
Exam 18: Digital Evidence on Unix Systems30 Questions
Exam 19: Digital Evidence on Macintosh Systems29 Questions
Exam 20: Digital Evidence on Mobile Devices32 Questions
Exam 21: Network Basics for Digital Investigators33 Questions
Exam 22: Applying Forensic Science to Networks35 Questions
Exam 23: Digital Evidence on the Internet30 Questions
Exam 24: Digital Evidence at the Physical and Data-Link Layers34 Questions
Exam 25: Digital Evidence at the Network and Transport Layers30 Questions
Select questions type
A forensic examiner would use logical access to examine media if the file and directory structures were to be analyzed.
(True/False)
4.7/5
(31)
You find the following deleted file on a floppy disk. How many clusters does this file occupy? Name Ext ID Size Date Time Cluster 76 A R S H D V \_REENF \sim1 DOC Erased 19968 5-08-03 2:34pm 275 A----
(Multiple Choice)
4.9/5
(41)
Which of the following issues is NOT one that a forensic examiner faces when dealing with Windows-based media?
(Multiple Choice)
4.8/5
(40)
The MD5 hashing algorithm is no longer considered to be a reliable method for determining whether two blocks of text are identical.
(True/False)
4.9/5
(38)
EnCase provides the means to create a Windows Evidence Acquisition Boot Disk to allow for network acquisition of an evidence drive.
(True/False)
5.0/5
(37)
Just like Windows NT, Windows 98 has event logs that record system activities.
(True/False)
4.9/5
(38)
When examining the Windows registry key, the "Last Write Time" indicates:
(Multiple Choice)
4.7/5
(45)
Showing 21 - 30 of 30
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)