New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

GD0-100 Certification Exam For ENCE North America Questions and Answers

Questions 4

An Enhanced Metafile would best be described as:

Options:

A.

A compressed zip file.

B.

A graphics file attached to an e-mail message.

C.

A compound e-mail attachment.

D.

A file format used in the printing process by Windows.

Buy Now
Questions 5

How many partitions can be found in the boot partition table found at the beginning of the drive?

Options:

A.

8

B.

4

C.

6

D.

2

Buy Now
Questions 6

You are examining a hard drive that has Windows XP installed as the operating system. You see a file that has a date and time in the deleted column. Where does that date and time come from?

Options:

A.

Directory Entry

B.

Master File Table

C.

Info2 file

D.

Inode Table

Buy Now
Questions 7

When a document is printed using EMF in Windows, what file(s) are generated in the spooling process?

Options:

A.

The .SHD file

B.

The .SPL file

C.

Neither a or b

D.

Both a and b

Buy Now
Questions 8

GREP terms are automatically recognized as GREP by EnCase.

Options:

A.

True

B.

False

Buy Now
Questions 9

The case number in an evidence file can be changed without causing the verification feature to report an error, if:

Options:

A.

The user utilizes a text editor.

B.

The case information cannot be changed in an evidence file, without causing the verification feature to report an error.

C.

The user utilizes the case information editor within EnCase.

D.

The evidence file is reacquired.

Buy Now
Questions 10

To generate an MD5 hash value for a file, EnCase:

Options:

A.

Computes the hash value including the logical file and filename.

B.

Computes the hash value including the physical file and filename.

C.

Computes the hash value based on the logical file.

D.

Computes the hash value based on the physical file.

Buy Now
Questions 11

An evidence file can be moved to another directory without changing the file verification.

Options:

A.

False

B.

True

Buy Now
Questions 12

Within EnCase for Windows, the search process is:

Options:

A.

a search of the physical disk in unallocated clusters and other unused disk areas

B.

a search of the logical files

C.

None of the above

D.

both a and b

Buy Now
Questions 13

A signature analysis has been run on a case. The result ?*JPEG ?in the signature column means:

Options:

A.

The file signature is unknown and the header is a JPEG.

B.

The file signature is a JPEG signature and the file extension is incorrect.

C.

The file signature is unknown and the file extension is JPEG.

D.

None of the above.

Buy Now
Questions 14

In DOS acquisition mode, if a physical drive is detected, but no partition information is displayed, what would be the cause:

Options:

A.

Both a and b

B.

The partition scheme is not recognized by DOS.

C.

Neither a or b

D.

There are no partitions present.

Buy Now
Questions 15

If cluster #3552 entry in the FAT table contains a value of ?? this would mean:

Options:

A.

The cluster is unallocated

B.

The cluster is the end of a file

C.

The cluster is allocated

D.

The cluster is marked bad

Buy Now
Questions 16

A SCSI drive is pinned as a master when it is:

Options:

A.

The only drive on the computer.

B.

The primary of two drives connected to one cable.

C.

Whenever another drive is on the same cable and is pinned as a slave.

D.

A SCSI drive is not pinned as a master.

Buy Now
Questions 17

Before utilizing an analysis technique on computer evidence, the investigator should:

Options:

A.

Test the technique on simulated evidence in a controlled environment to confirm that the results are consistent.

B.

Be trained in the employment of the technique.

C.

Botha and b.

D.

Neithera or b.

Buy Now
Questions 18

A case file can contain ____ hard drive images?

Options:

A.

5

B.

1

C.

any number of

D.

10

Buy Now
Questions 19

The Windows 98 Start Menu has a selection called documents which displays a list of recently used files. Which of the following The Windows 98 Start Menu has a selection called documents which displays a list of recently used files. Which of the following folders contain those files?

Options:

A.

C:\Windows\History

B.

C:\Windows\Start menu\Documents

C.

C:\Windows\Documents

D.

C:\Windows\Recent

Buy Now
Questions 20

When a file is deleted in the FAT file system, what happens to the filename?

Options:

A.

It is zeroed out.

B.

The first character of the directory entry is marked with a hex 00.

C.

It is wiped from the directory.

D.

The first character of the directory entry is marked with a hex E5.

Buy Now
Questions 21

In the EnCase environment, the term xternal viewers?is best described as: In the EnCase environment, the term ?xternal viewers?is best described as:

Options:

A.

Programs that are exported out of an evidence file.

B.

Any program that will work with EnCase.

C.

Any program that is loaded on the lab hard drive.

D.

Programsthat are associated with EnCase to open specific file types.

Buy Now
Questions 22

Search terms are case sensitive by default.

Options:

A.

False

B.

True

Buy Now
Questions 23

A logical file would be best described as:

Options:

A.

The data taken from the starting cluster to the end of the last cluster that is occupied by the file.

B.

A file including any RAM and disk slack.

C.

A file including only RAM slack.

D.

The data from the beginning of the starting cluster to the length of the file.

Buy Now
Questions 24

If cluster number 10 in the FAT contains the number 55, this means:

Options:

A.

That cluster 10 is used and the file continues in cluster number 55.

B.

That the file starts in cluster number 55 and continues to cluster number 10.

C.

That there is a cross-linked file.

D.

The cluster number 55 is the end of an allocated file.

Buy Now
Questions 25

If a hash analysis is run on a case, EnCase:

Options:

A.

Will compute a hash value of the evidence file and begin a verification process.

B.

Will generate a hash set for every file in the case.

C.

Will compare the hash value of the files in the case to the hash library.

D.

Will create a hash set to the user specifications. Will create a hash set to the user?specifications.

Buy Now
Questions 26

A standard Windows 98 boot disk is acceptable for booting a suspect drive.

Options:

A.

True

B.

False

Buy Now
Exam Code: GD0-100
Exam Name: Certification Exam For ENCE North America
Last Update: Dec 25, 2024
Questions: 176
GD0-100 pdf

GD0-100 PDF

$25.5  $84.99
GD0-100 Engine

GD0-100 Testing Engine

$30  $99.99
GD0-100 PDF + Engine

GD0-100 PDF + Testing Engine

$40.5  $134.99