Assume that MyNote.txt has been deleted. The FAT file system directory entry for that file has been overwritten. The data for MyNote.txt is now:
A. Overwritten
B. Allocated
C. Cross-linked
D. Unallocated
A hard drive was imaged using EnCase. The original drive was placed into evidence. The restore feature was used to make a copy of the original hard drive. EnCase verifies the restored copy using:
A. An MD5 hash
B. A 32 bit CRC
C. Nothing. Restored volumes are not verified.
D. A running log
A restored floppy diskette will have the same hash value as the original diskette.
A. True
B. False
During the power-up sequence, which of the following happens first?
A. The boot sector is located on the hard drive.
B. Theower On Self-Test.? 7KH ? RZHU2Q6HOI7HVW
C. The floppy drive is checked for a diskette.
D. The BIOS on an add-in card is executed.
Which of the following is found in the FileSignatures.ini configuration file
A. The results of a hash analysis
B. The information contained in the signature table
C. The results of a signature analysis
D. Pointers to an evidence file
To generate an MD5 hash value for a file, EnCase:
A. Computes the hash value including the logical file and filename.
B. Computes the hash value including the physical file and filename.
C. Computes the hash value based on the logical file.
D. Computes the hash value based on the physical file.
When a non-compressed evidence file is reacquired with compression, the acquisition and verification hash values for the evidence will remain the same for both files.
A. True
B. False
In hexadecimal notation, one byte is represented by _____ character(s).
A. 2
B. 1
C. 8
D. 4
A personal data assistant was placed in a evidence locker until an examiner has time to examine it. Which of the following areas would require special attention?
A. Chain-of-custody
B. Storage
C. There is no concern
D. Cross-contamination
The EnCase methodology dictates that the lab drive for evidence have a __________ prior to making an image.
A. FAT 16 partition
B. NTFS partition
C. unique volume label
D. bare, unused partition
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Guidance Software exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your GD0-100 exam preparations and Guidance Software certification application, do not hesitate to visit our Vcedump.com to find your solutions here.