Free GD0-110 Exam Braindumps (page: 22)

Page 21 of 44

CORRECT TEXT
The case file should be archived with the evidence files at the termination of a case.

  1. True
  2. False
  3. The answer is Pending

Answer(s): C



How does EnCase verify that the evidence file contains an exact copy of the suspect hard drive? How does EnCase verify that the evidence file contains an exact copy of the suspect? hard drive?

  1. By means of a CRC value of the suspect hard drive compared to a CRC value of the data stored in the evidence file. By means of a CRC value of the suspect? hard drive compared to a CRC value of the data stored in the evidence file.
  2. By means of a CRC value of the evidence file itself.
  3. By means of an MD5 hash of the suspect hard drive compared to an MD5 hash of the data stored in the evidence file. By means of an MD5 hash of the suspect? hard drive compared to an MD5 hash of the data stored in the evidence file.
  4. By means of an MD5 hash value of the evidence file itself.

Answer(s): C



The case number in an evidence file can be changed without causing the verification feature to report an error, if:

  1. The user utilizes a text editor.
  2. The user utilizes the case information editor within EnCase.
  3. The evidence file is reacquired.
  4. The case information cannot be changed in an evidence file, without causing the verification feature to report an error.

Answer(s): D



The term ignature?and eader?as they relate to a signature analysis are: The term ?ignature?and ?eader?as they relate to a signature analysis are:

  1. Areas compared with each other to verify the correct file type.
  2. Synonymous.
  3. The signature is the file extension. The header is a standard pattern normally found at the beginning of a file.
  4. None of the above

Answer(s): B






Post your Comments and Discuss Guidance Software GD0-110 exam with other Community members:

GD0-110 Discussions & Posts