Free GD0-110 Exam Braindumps (page: 13)

Page 12 of 44

What information should be obtained from the BIOS during computer forensic investigations?

  1. The date and time
  2. The video caching information
  3. The port assigned to the serial port
  4. The boot sequence

Answer(s): A,D



In DOS acquisition mode, if a physical drive is detected, but no partition information is displayed, what would be the cause:

  1. Neither a or b
  2. Both a and b
  3. There are no partitions present.
  4. The partition scheme is not recognized by DOS.

Answer(s): B



A suspect typed a file on his computer and saved it to a floppy diskette. The filename was MyNote.txt. You receive the floppy and the suspect computer. The suspect denies that the floppy disk belongs to him. You search the suspect computer and locate only the suspect? computer. The suspect denies that the floppy disk belongs to him. You search the suspect? computer and locate only the filename within a .LNK file. The .LNK file is located in the folder C:\Windows\Recent. How you would use the .LNK file to establish a connection between the file on the floppy diskette and the suspect computer? connection between the file on the floppy diskette and the suspect? computer?

  1. The file signature found in the .LNK file
  2. The dates and time of the file found in the .LNK file, at file offset 28
  3. Both a and b
  4. The full path of the file, found in the .LNK file

Answer(s): C



Select the appropriate name for the highlighted area of the binary numbers.

  1. Nibble
  2. Dword
  3. Word
  4. Bit
  5. Byte

Answer(s): D






Post your Comments and Discuss Guidance Software GD0-110 exam with other Community members:

GD0-110 Discussions & Posts