Exam 17: Digital Evidence on Windows Systems

arrow
  • Select Tags
search iconSearch Question
  • Select Tags

A forensic examiner would use logical access to examine media if the file and directory structures were to be analyzed.

(True/False)
4.7/5
(31)

The Windows NT Event log Appevent.evt:

(Multiple Choice)
4.8/5
(34)

You find the following deleted file on a floppy disk. How many clusters does this file occupy? Name Ext ID Size Date Time Cluster 76 A R S H D V \_REENF \sim1 DOC Erased 19968 5-08-03 2:34pm 275 A----

(Multiple Choice)
4.9/5
(41)

Which of the following issues is NOT one that a forensic examiner faces when dealing with Windows-based media?

(Multiple Choice)
4.8/5
(40)

The Windows NT Event log Secevent.evt:

(Multiple Choice)
4.8/5
(38)

The MD5 hashing algorithm is no longer considered to be a reliable method for determining whether two blocks of text are identical.

(True/False)
4.9/5
(38)

EnCase provides the means to create a Windows Evidence Acquisition Boot Disk to allow for network acquisition of an evidence drive.

(True/False)
5.0/5
(37)

Just like Windows NT, Windows 98 has event logs that record system activities.

(True/False)
4.9/5
(38)

File system traces include all of the following EXCEPT:

(Multiple Choice)
5.0/5
(44)

When examining the Windows registry key, the "Last Write Time" indicates:

(Multiple Choice)
4.7/5
(45)
Showing 21 - 30 of 30
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)