The spool files that are created during a print job are __________ after the print job is completed.
When a drive letter is assigned to a logical volume, that information is temporarily written the volume boot record on the hard drive.
Which of the following would be a true statement about the function of the BIOS?
For an EnCase evidence file acquired with a hash value to pass verification, which of the following must be true?
Calls to the C:\ volume of the hard drive are not made by DOS when a computer is booted with a standard DOS 6.22 boot disk.
Before utilizing an analysis technique on computer evidence, the investigator should:
How does EnCase verify that the case information (Case Number, Evidence Number, Investigator Name, etc) in an evidence file has not been damaged or changed, after the evidence file has been written?
To undelete a file in the FAT file system, EnCase computes the number of _______ the file will use based on the file ______.
You are working in a computer forensic lab. A law enforcement investigator brings you a computer and a valid search warrant. You have legal authority to search the computer. The investigator hands you a piece of paper that has three printed checks on it. All three checks have the same check and account number. You image the suspect computer and open the evidence file with EnCase. You checks have the same check and account number. You image the suspect's computer and open the evidence file with EnCase. You perform a text search for the account number and check number. Nothing returns on the search results. You perform a text search for all other information found on the printed checks and there is still nothing returned in the search results. You run a signature analysis and check the gallery. You cannot locate any graphical copies of the printed checks in the gallery. At this point, is it safe to say that the checks are not located on the suspect computer?
The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. [^a-z] Tom[^a-z]
The EnCase signature analysis is used to perform which of the following actions?
When a file is deleted in the FAT or NTFS file systems, what happens to the data on the hard drive?
Pressing the power button on a computer that is running could have which of the following results?