Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

GD0-110 Certification Exam for EnCE Outside North America Questions and Answers

Questions 4

This question addresses the EnCase for Windows search process. If a target word is within a logical file, and it begins in cluster 10 and ends in cluster 15 (the word is fragmented), the search:

Options:

A.

Will not find it because the letters of the keyword are not contiguous.

B.

Will not find it unless File slack is checked on the search dialog box.

C.

Will find it because EnCase performs a logical search.

D.

Will not find it because EnCase performs a physical search only.

Buy Now
Questions 5

The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. [^a-z]Tom[^a-z]

Options:

A.

Stomp

B.

Tomato

C.

Tom

D.

Toms

Buy Now
Questions 6

You are investigating a case involving fraud. You seized a computer from a suspect who stated that the computer is not used by anyone other than himself. The computer has Windows 98 installed on the hard drive. You find the filename C:\downloads\check01.jpg?that EnCase shows as being moved. The starting extent is 0C4057. You find another filename C:\downloads\chk1.dll with the starting extent 0C4057, which EnCase also shows as being moved. In the C:\windows\System folder you find an allocated file named chk1.dll with the starting extent 0C4057. The chk1.dll file is a JPEG image of a counterfeit check. Could this information be used to refute the suspect claim that he never knew it was on the computer?

Options:

A.

Yes, because the chk1.dll file was moved and renamed.

B.

No, because the Windows operating system likely moved and renamed the chk1.dll file during disk maintenance.

C.

No, because the chk1.dll file has no evidentiary value.

D.

Yes, because the ch1.dll is all the evidence required to prove the case.

Buy Now
Questions 7

A sector on a floppy disk is the same size as a sector on a NTFS formatted hard drive.

Options:

A.

True

B.

False

Buy Now
Questions 8

An evidence file can be moved to another directory without changing the file verification.

Options:

A.

True

B.

False

Buy Now
Questions 9

A standard Windows 98 boot disk is acceptable for booting a suspect drive.

Options:

A.

True

B.

False

Buy Now
Questions 10

Search terms are case sensitive by default.

Options:

A.

True

B.

False

Buy Now
Questions 11

A signature analysis has been run on a case. The result ?*JPEG ?in the signature column means:

Options:

A.

The file signature is unknown and the file extension is JPEG.

B.

The file signature is unknown and the header is a JPEG.

C.

The file signature is a JPEG signature and the file extension is incorrect.

D.

None of the above.

Buy Now
Questions 12

To later verify the contents of an evidence file?

Options:

A.

EnCase writes an MD5 hash value for every 32 sectors copied.

B.

EnCase writes a CRC value for every 64 sectors copied.

C.

EnCase writes a CRC value for every 128 sectors copied.

D.

EnCase writes an MD5 hash value every 64 sectors copied.

Buy Now
Questions 13

Within EnCase, what is purpose of the default export folder?

Options:

A.

This is the folder that will automatically store an evidence file when the acquisition is made in DOS.

B.

This is the folder that temporarily stores all bookmark and search results.

C.

This is the folder used to hold copies of files that are sent to external viewers.

D.

This is the folder that will be automatically selected when the copy/unerase feature is used.

Buy Now
Questions 14

A personal data assistant was placed in a evidence locker until an examiner has time to examine it. Which of the following areas would require special attention?

Options:

A.

Cross-contamination

B.

Storage

C.

Chain-of-custody

D.

There is no concern

Buy Now
Questions 15

How many clusters can a FAT 16 system address?

Options:

A.

4,096

B.

65,536

C.

268,435,456

D.

4,294,967,296

Buy Now
Questions 16

RAM is used by the computer to:

Options:

A.

Permanently store electronic data.

B.

Execute the POST during start-up.

C.

Temporarily store electronic data that is being processed.

D.

Establish a connection with external devices.

Buy Now
Questions 17

Which of the following is commonly used to encode e-mail attachments?

Options:

A.

JPEG

B.

GIF

C.

EMF

D.

Base64

Buy Now
Questions 18

What information in a FAT file system directory entry refers to the location of a file on the hard drive?

Options:

A.

The file size

B.

The file attributes

C.

The starting cluster

D.

The fragmentation settings

Buy Now
Questions 19

In the EnCase environment, the term uxternal viewers is best described as:

Options:

A.

Programs that are exported out of an evidence file.

B.

Programs that are associated with EnCase to open specific file types.

C.

Any program that is loaded on the lab hard drive.

D.

Any program that will work with EnCase.

Buy Now
Questions 20

Assume that an evidence file is added to a case, the case is saved, and the case is closed. What happens if the evidence file is moved, and the case is then opened?

Options:

A.

EnCase reports that the file integrity has been compromised and renders the file useless.

B.

EnCase reports a different hash value for the evidence file.

C.

EnCase asks for the location of the evidence file the next time the case is opened.

D.

EnCase opens the case, excluding the moved evidence.

Buy Now
Questions 21

In DOS and Windows, how many bytes are in one FAT directory entry?

Options:

A.

8

B.

16

C.

32

D.

64

E.

Variable

Buy Now
Questions 22

Which of the following is found in the FileSignatures.ini configuration file?

Options:

A.

Pointers to an evidence file

B.

The results of a signature analysis

C.

The results of a hash analysis

D.

The information contained in the signature table

Buy Now
Questions 23

Which of the following selections is NOT found in the case file?

Options:

A.

External viewers

B.

Pointers to evidence files

C.

Signature analysis results

D.

Search results

Buy Now
Questions 24

Calls to the C:\ volume of the hard drive are not made by DOS when a computer is booted with a standard DOS 6.22 boot disk.

Options:

A.

True

B.

False

Buy Now
Questions 25

Which of the following selections would be used to keep track of a fragmented file in the FAT file system?

Options:

A.

The File Allocation Table

B.

The directory entry for the fragmented file

C.

The partition table of extents

D.

All of the above

Buy Now
Exam Code: GD0-110
Exam Name: Certification Exam for EnCE Outside North America
Last Update: Nov 24, 2024
Questions: 174
GD0-110 pdf

GD0-110 PDF

$25.5  $84.99
GD0-110 Engine

GD0-110 Testing Engine

$30  $99.99
GD0-110 PDF + Engine

GD0-110 PDF + Testing Engine

$40.5  $134.99