EnCase Environment - Review Questions

20 important questions on EnCase Environment - Review Questions

In the EnCase Windows environment, must an examiner first create a new case before adding a device to examine?

A. Yes
B. No

A.  Yes, Your must first create a new case before the Add Device option is available.

When EnCase 7 is used to create a new case, which files are created automatically in the case folder under the folder bearing the name of the case?

A. Evidence, Export, Temp, and Index folders
B. Export, Temp, and Index folders
C. Email, Export, Tags, and Temp
D. Evidence, Email, Tags, and Temp

C.  EnCase7 creates Email, Export, Tags and Temp.  The Evidence folder would
      have to be created manually by the user if the user opted to place it in this
      location.

From the EnCase 7 Home screen, which of the following cannot be carried out?

A. Opening a case
B. Creating a new case
C. Opening options
D. Generating a encryption key
E. All of the above

E.  A, B, C, and D can all be carried out from the  Home screen.
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart

When creating a new case, the Case Options dialog box prompts for which of the following?

A. Name (case name)
B. Examiner name
C. Base case folder path
D. Primary evidence cache path
E. All of the above

E.  The Case Options dialog box asks for all the options listed when a new
      case is created.

What determines the action that will result when a user double-clicks a file within EnCase?

A. The settings in the TEXTSTYLES.INI file
B. The settings in the FILETYPES.INI file
C. The settings in the FILESIGNATURES.INI file
D. The settings in the VIEWERS.INI file

B. The data in the File Types database (stored in the FILETYPES>INI file)
     determines which file types will be opened by which viewers upon
     double-clicking or opening the file.

In the EnCase environment, the term external viewers is best described as which of the following?

A. Internal programs that are copied out of an evidence file
B. External programs loaded in the evidence file to open specific file types
C. External programs that are associated with EnCase to open specific file types
D. External viewers used to open a file that has been copied out of an evidence
     file

C. External viewers are programs that EnCase uses to open specific file types
     and are configured by the user.

Where is the list of external viewers kept within EnCase?

A. The settings in the TEXTSTYLES.INI file
B. The settings in the FILETYPES.INI file
C. The settings in the XTERNALVIEWERS.CFG file
D. The settings in the VIEWERS.INI file

D.  The VIEWERS.INI file stores information external programs that EnCase
      uses to open specific file types.

When EnCase sends a file to an external viewer, to which folder does it send the file?

A. Scratch
B. Export
C. Temp
D. None of the above

C.  When EnCase sends a file to an external viewer, the file is placed in the
      temp folder.

How is the Disk view launched?

A. By simply switching to the Disk view tab on the Table pane
B. By launching it from the Device menu
C. By right-clicking the device and choosing Open With Disk Viewer
D. None of the above

B.  It is launched as an option from the Device menu.

Which of the following is true about the Gallery view?

A. Files that are determined to be images by their file extension will be
     displayed.
B. Files that are determined to be images based on file signature analysis will
     be displayed after the EnCase evidence processor has been run.
C. Files displayed in the Gallery view are determined by where you place the
     focus in the Tree pane or where you activate the Set-Included
     Folders feature.D. All of the above.

D.  All are true regarding the Gallery view.

True or false? The right-side menu is a collection of the menus and tools found on its toolbar.

A. True
B. False

A.  True - the right-side menu is a collection of the menus and tools found on the
      toolbar to its left.  It is akin to the content formerly found on the right-click
       mouse button.

True or false? The results of conditions and filters are seen immediately in the Table pane of the Evidence tab Entries view.

A. True
B. False

B.  False - When a filter or condition is run, The results are shown in the Results
     view or tab.

How do you access the setting to adjust how often a backup file (.cbak) is saved?

A. Select Tools a Options a Case Options.
B. Select View a Options a Case Options.
C. Select Tools a Options a Global.
D. Select View a Options a Global.

C.  To adjust the amount of minutes the backup files is saved, select Tools in the
      menu bar, select Options, and then change the time in the Auto Save Minutes
      box on the Global tab of the resulting dialog box.

What is the maximum number of columns that can be sorted simultaneously in the Table view tab?

A. Two
B. Three
C. Six
D. 28 (maximum number of tabs)

C.  Six,  Encase allows the user to sort up to six columns in the Table view tab.

How would a user reverse-sort on a column in the Table view?

A. Hold down the Ctrl key, and double-click the selected column header.
B. Right-click the selected column, select Sort, and select either Sort Ascending
     or Sort Descending.
C. Both A and B.

C.  The user can use either method to revers-sort on a column.

How can you hide a column in the Table view?

A. Place the cursor on the selected column, and press Ctrl+H.
B. Place cursor on the selected column, open Columns menu on the
    toolbar, and select Hide.
C. Place cursor on the selected column, open the right-side menu, open
     the Columns submenu, and select Hide.
D. Open the right-side menu, open the Columns submenu, select Show
     Columns, and uncheck the desired fields to be hidden.
E. All of the above.

E.  All four methods will hide selected columns from the Table view.

What does the Gallery view tab use to determine graphics files?

A. Header or file signature
B. File extension
C. Filename
D. File size

B.  The Gallery view displays images based on the File Category - Picture setting,
     which is determined by the file extensions until such time that ta file
      signature analysis is run.

Will the EnCase Gallery view display a .jpeg file if its file extension was renamed to .txt?

A. No, because EnCase will treat it as a text file
B. Yes, because the Gallery view looks at a file’s header information and not
     the file extension
C. Yes, but only if a signature analysis is performed to correct the File
     Category to Picture based on its file header information
D. Yes, but only after a hash analysis is performed to determine the file’s
     true identity

C.  When a signature analysis is performed, EnCase will update or correct
      the file category to Picture, in this particular case, based on the
      information contained in the file header.

How would a user change the default colors and text fonts within EnCase?

A. The user cannot change the default colors and fonts settings.
B. The user can change the default colors and fonts settings by right-clicking
     the selected items and scrolling down to Change Colors and Fonts.
C. The user can change the default colors and fonts settings by clicking
     the View tab on the menu bar and selecting the Colors tab or Fonts tab.
D. The user can change default colors and fonts settings by clicking the Tools

D.  A user can change the way colors and fonts appear by selecting the
      Tools tab and the clicking Options to change colors and fonts.

An EnCase user will always know the exact location of the selected data
in the evidence file by looking at which of the following?

A. Navigation Data on status bar
B. Dixon box
C. Disk view
D. Hex view

A.  Navigation Data (also called the GPS bar in the field) displays the selected
     data's exact location, including the full path, physical sector, logical sector
     number, cluster number, sector offset, and file offset.

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo