Which of the following selections would be used to keep track of a fragmented file in the FAT file system?
A. All of the above
B. The partition table of extents
C. The File Allocation Table
D. The directory entry for the fragmented file
Which of the following would be a true statement about the function of the BIOS?
A. The BIOS is responsible for checking and configuring the system after the power is turned on.
B. Botha and c.
C. The BIOS is responsible for swapping out memory pages when RAM fills up.
D. The BIOS integrates compressed executable files with memory addresses for faster execution.
The EnCase default export folder is:
A. A global setting that cannot be changed.
B. A case-specific setting that can be changed.
C. A global setting that can be changed.
D. A case-specific setting that cannot be changed.
Consider the following path in a FAT file system:
A. From the root directory c:\
B. From itself
C. From the My Pictures directory
D. From the My Documents directory
The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. 800[) \-]+555-1212
A. 800-555 1212
B. 800.555.1212
C. 8005551212
D. (800) 555-1212
The EnCase methodology dictates that be created prior to acquiring evidence.
A. a text file for notes
B. a unique directory on the lab drive for case management
C. an .E01 file on the lab drive
D. All of the above
Select the appropriate name for the highlighted area of the binary numbers.
A. Nibble
B. Dword
C. Word
D. Byte
E. Bit
To generate an MD5 hash value for a file, EnCase: A. Computes the hash value based on the physical file.
B. Computes the hash value including the physical file and filename.
C. Computes the hash value including the logical file and filename.
D. Computes the hash value based on the logical file.
The EnCase methodology dictates that the lab drive for evidence have a prior to making an image.
A. NTFS partition
B. unique volume label
C. FAT 16 partition
D. bare, unused partition