Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: netbudy65

GD0-110 Certification Exam for EnCE Outside North America Questions and Answers

Questions 4

The end of a logical file to the end of the cluster that the file ends in is called:

Options:

A.

Unallocated space

B.

Allocated space

C.

Available space

D.

Slack

Buy Now
Questions 5

Select the appropriate name for the highlighted area of the binary numbers.

Options:

A.

Word

B.

Nibble

C.

Bit

D.

Dword

E.

Byte

Buy Now
Questions 6

The FAT in the File Allocation Table file system keeps track of:

Options:

A.

File fragmentation

B.

Every addressable cluster on the partition

C.

Clusters marked as bad

D.

All of the above.

Buy Now
Questions 7

A FAT directory has as a logical size of:

Options:

A.

0 bytes

B.

64 bytes

C.

128 bytes

D.

One cluster

Buy Now
Questions 8

Temp files created by EnCase are deleted when EnCase is properly closed.

Options:

A.

True

B.

False

Buy Now
Questions 9

Within EnCase for Windows, the search process is:

Options:

A.

a search of the logical files

B.

a search of the physical disk in unallocated clusters and other unused disk areas

C.

both a and b

D.

None of the above

Buy Now
Questions 10

The results of a hash analysis on an evidence file that has been added to a case will be stored in which of the following files?

Options:

A.

The case file

B.

The configuration HashAnalysis.ini file

C.

The evidence file

D.

All of the above

Buy Now
Questions 11

The EnCase evidence file logical filename can be changed without affecting the verification of the acquired evidence.

Options:

A.

True

B.

False

Buy Now
Questions 12

Calls to the C:\ volume of the hard drive are not made by DOS when a computer is booted with a standard DOS 6.22 boot disk.

Options:

A.

True

B.

False

Buy Now
Questions 13

By default, what color does EnCase use for slack?

Options:

A.

Black

B.

Red

C.

Black on red

D.

Red on black

Buy Now
Questions 14

A hash set would most accurately be described as:

Options:

A.

A group of hash libraries organized by category.

B.

A table of file headers and extensions.

C.

A group of hash values that can be added to the hash library.

D.

Both a and b.

Buy Now
Questions 15

In the EnCase environment, the term uxternal viewers is best described as:

Options:

A.

Programs that are exported out of an evidence file.

B.

Programs that are associated with EnCase to open specific file types.

C.

Any program that is loaded on the lab hard drive.

D.

Any program that will work with EnCase.

Buy Now
Questions 16

When a file is deleted in the FAT or NTFS file systems, what happens to the data on the hard drive?

Options:

A.

It is overwritten with zeroes.

B.

It is moved to a special area.

C.

Nothing.

D.

The file header is marked with a Sigma so the file is not recognized by the operating system.

Buy Now
Questions 17

When a non-compressed evidence file is reacquired with compression, the acquisition and verification hash values for the evidence will remain the same for both files.

Options:

A.

True

B.

False

Buy Now
Questions 18

The spool files that are created during a print job are __________ after the print job is completed.

Options:

A.

wiped

B.

deleted and wiped

C.

deleted

D.

moved

Buy Now
Questions 19

A standard Windows 98 boot disk is acceptable for booting a suspect drive.

Options:

A.

True

B.

False

Buy Now
Questions 20

In Windows, the file MyNote.txt is deleted from C Drive and is automatically sent to the recycle Bin. The long filename was MyNote.txt and the short filename was MYNOTE.TXT. When viewing the recycle Bin with EnCase, how will the long filename and short filename appear?

Options:

A.

MyNote.del, DC0.del

B.

MyNote.txt, CD0.txt

C.

MyNote.txt, DC0.txt

D.

MyNote.del, DC1.del

Buy Now
Questions 21

ROM is an acronym for:

Options:

A.

Read Only Memory

B.

Random Open Memory

C.

Relative Open Memory

D.

Read Open Memory

Buy Now
Questions 22

When an EnCase user double-clicks on a valid .jpg file, that file is:

Options:

A.

Copied to the EnCase specified temp folder and opened by an associated program.

B.

Copied to the default export folder and opened by an associated program.

C.

Opened by EnCase.

D.

Renamed to JPG_0001.jpg and copied to the default export folder.

Buy Now
Questions 23

You are investigating a case involving fraud. You seized a computer from a suspect who stated that the computer is not used by anyone other than himself. The computer has Windows 98 installed on the hard drive. You find the filename C:\downloads\check01.jpg?that EnCase shows as being moved. The starting extent is 0C4057. You find another filename C:\downloads\chk1.dll with the starting extent 0C4057, which EnCase also shows as being moved. In the C:\windows\System folder you find an allocated file named chk1.dll with the starting extent 0C4057. The chk1.dll file is a JPEG image of a counterfeit check. Could this information be used to refute the suspect claim that he never knew it was on the computer?

Options:

A.

Yes, because the chk1.dll file was moved and renamed.

B.

No, because the Windows operating system likely moved and renamed the chk1.dll file during disk maintenance.

C.

No, because the chk1.dll file has no evidentiary value.

D.

Yes, because the ch1.dll is all the evidence required to prove the case.

Buy Now
Questions 24

To undelete a file in the FAT file system, EnCase computes the number of _______ the file will use based on the file ______.

Options:

A.

Clusters; starting extent

B.

Sectors; starting extent

C.

Sectors; file size

D.

Clusters; file size

Buy Now
Questions 25

Which of the following directories contain the information that is found on a Windows 98 Desktop?

Options:

A.

C:\Windows\Desktop

B.

C:\Desktop

C.

C:\Program files\Programs\Desktop

D.

C:\Startup\Desktop\Items

Buy Now
Questions 26

A sector on a hard drive contains how many bytes?

Options:

A.

512

B.

1024

C.

2048

D.

4096

Buy Now
Exam Code: GD0-110
Exam Name: Certification Exam for EnCE Outside North America
Last Update: Dec 4, 2024
Questions: 174

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99