EnCase Certified Examiner (EnCE) Certification Exam — Questions and Answers
Question 1: What forensic artifact can confirm that a suspect visited a website using a browser's 'Reader Mode' feature?
- Browser history entries showing the reader-mode URL scheme (e.g., about:reader?url=) (Correct answer)
- A separate reader-mode database file
- A dedicated reader-mode registry key
- Windows Prefetch files with a 'READER' prefix
Correct answer: Browser history entries showing the reader-mode URL scheme (e.g., about:reader?url=)
Reader Mode URLs are stored in browser history with a distinctive scheme such as 'about:reader?url=' prepended to the original URL, confirming the feature was used.
Question 2: When referencing EnCase bookmarks in a formal report, the examiner should ensure that:
- Bookmarks are only used in internal notes, never in court reports
- Bookmarks are deleted after the report is finalized
- Bookmark descriptions are written by legal counsel
- Each bookmark reference corresponds to a verifiable location within the acquired evidence file (Correct answer)
Correct answer: Each bookmark reference corresponds to a verifiable location within the acquired evidence file
Every bookmark referenced in the report must map to a verifiable, reproducible location within the forensic image so opposing counsel or another examiner can independently verify the finding.
Question 3: What is the recommended procedure when an examiner discovers a running computer with an encrypted volume that is currently mounted?
- Immediately hibernate the system to save the encryption keys in the hiberfil.sys
- Pull the power to preserve the encrypted state for later analysis
- Perform live memory acquisition first to capture encryption keys, then image the drive (Correct answer)
- Reboot into a forensic boot environment before imaging
Correct answer: Perform live memory acquisition first to capture encryption keys, then image the drive
Live memory acquisition can capture encryption keys stored in RAM, enabling later decryption of the volume — pulling power would lose this critical evidence.
Question 4: In EnCase, what is the function of the 'Bookmark' feature?
- It marks files for deletion from the evidence container
- It encrypts selected files within the case
- It sets the evidence file's hash verification status
- It tags and annotates specific items or data regions for inclusion in reports (Correct answer)
Correct answer: It tags and annotates specific items or data regions for inclusion in reports
Bookmarks allow examiners to flag, annotate, and organize key evidence items so they can be easily referenced and included in final reports.
Question 5: When packaging physical evidence for transport to a lab, which environmental hazard poses the greatest risk to hard drives?
- Exposure to cold temperatures below 32°F
- Vibration during transport
- Humidity above 50%
- Electrostatic discharge (ESD) (Correct answer)
Correct answer: Electrostatic discharge (ESD)
Electrostatic discharge can destroy drive electronics; anti-static bags and proper grounding are essential when handling drives.
Question 6: When analyzing a mobile device's call logs in EnCase, which Android database file would the examiner typically target?
- dialer/history.xml
- system/phone_log.sqlite
- telephony/mmssms.db
- contacts2.db or calllog.db (Correct answer)
Correct answer: contacts2.db or calllog.db
Android call logs are stored in the contacts2.db or a separate calllog.db file managed by the CallLog content provider.
Question 7: What is the most important element of effective professional communication in EnCE?
- Clarity and audience-appropriate language (Correct answer)
- Writing lengthy documents
- Using complex vocabulary
- Avoiding all technical terms
Correct answer: Clarity and audience-appropriate language
Effective communication requires clarity and language appropriate for the audience to ensure the message is understood as intended.
Question 8: What distinguishes a EnCase Certified Examiner certified professional from a non-certified practitioner?
- Certified professionals exclusively work in larger organizations
- There is no meaningful difference in competency
- Certification validates competency through standardized assessment against established benchmarks (Correct answer)
- Certified professionals always have more years of experience
Correct answer: Certification validates competency through standardized assessment against established benchmarks
Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.
Question 9: What is the purpose of imaging a drive's Host Protected Area (HPA)?
- To acquire the drive's firmware partition
- To recover deleted files from the file system
- To verify the drive's S.M.A.R.T. data
- To capture potentially hidden data that the OS cannot normally access (Correct answer)
Correct answer: To capture potentially hidden data that the OS cannot normally access
The HPA is a portion of the drive hidden from the operating system; imaging it can reveal data intentionally concealed by suspects.
Question 10: Which scenario represents a violation of the EnCase Certified Examiner code of professional conduct?
- Seeking continuing education beyond minimum requirements
- Misrepresenting qualifications or certification status (Correct answer)
- Declining work outside one's area of competence
- Reporting safety concerns to regulatory authorities
Correct answer: Misrepresenting qualifications or certification status
Misrepresenting qualifications or certification status is a serious violation of professional conduct. It undermines public trust and can lead to harm when unqualified individuals perform specialized work.
Question 11: A EnCE certified professional is asked to provide services outside their scope of competence. The CORRECT ethical response is to:
- Decline and refer to a qualified professional (Correct answer)
- Accept and learn as they go
- Accept but charge a lower rate
- Accept the work to gain new experience
Correct answer: Decline and refer to a qualified professional
Ethical practice requires professionals to work within their scope of competence. Accepting work beyond one's qualifications can lead to substandard results and potential harm. Referring to qualified professionals ensures proper service delivery.
Question 12: During a network forensic investigation, an examiner notices beaconing behavior in firewall logs — periodic outbound connections to the same external IP at regular intervals. This is most consistent with which threat?
- A scheduled software update process only
- Malware maintaining a command-and-control (C2) channel (Correct answer)
- A misconfigured NTP server
- Normal web browsing patterns
Correct answer: Malware maintaining a command-and-control (C2) channel
Regular, periodic beaconing to an external IP is a hallmark of C2 malware checking in with its controller on a set schedule.
Question 13: What is the purpose of a 'preservation letter' sent to a third-party service provider during an investigation?
- To compel immediate production of records under penalty of contempt
- To request voluntary preservation of specified records pending formal legal process (Correct answer)
- To notify the provider that a subpoena has been filed with the court
- To transfer jurisdiction over the investigation to the provider's home state
Correct answer: To request voluntary preservation of specified records pending formal legal process
A preservation letter requests that a provider voluntarily preserve specified data while formal legal process (subpoena or warrant) is being obtained.
Question 14: In an EnCE-level forensic report, how should an examiner handle evidence that is exculpatory (favorable to the subject)?
- Include all exculpatory findings with the same rigor as inculpatory findings (Correct answer)
- Mention it only in a verbal briefing to the attorney
- Omit it to simplify the report
- Include it only if requested by the defense
Correct answer: Include all exculpatory findings with the same rigor as inculpatory findings
Professional forensic examiners must report all material findings including exculpatory evidence with equal rigor, as withholding such evidence is unethical and potentially unlawful.
Question 15: When facing an ethical dilemma in EnCE practice, what is the recommended first step?
- Ask colleagues to decide
- Avoid making any decision
- Follow personal preferences
- Identify the relevant ethical principles and stakeholders (Correct answer)
Correct answer: Identify the relevant ethical principles and stakeholders
Identifying the relevant ethical principles and all affected stakeholders provides a framework for systematic ethical analysis.
Question 16: What does the term 'smear' refer to in the context of memory acquisition?
- Contamination of the hard drive during imaging
- A method to overwrite sensitive data before imaging
- Inconsistencies in a memory image caused by changes in RAM during acquisition (Correct answer)
- A type of malware that corrupts memory dumps
Correct answer: Inconsistencies in a memory image caused by changes in RAM during acquisition
Memory smear occurs because RAM contents change continuously during acquisition; the resulting image may contain data from different points in time, creating inconsistencies.
Question 17: When EnCase identifies Internet history artifacts in a forensic investigation, how should the examiner represent browser cache data in the report?
- As deleted data with no probative value
- As confirmed user visits with timestamps
- As artifacts recovered from cache with a note that cache population can be automated (Correct answer)
- As proof of deliberate user intent to visit the site
Correct answer: As artifacts recovered from cache with a note that cache population can be automated
Browser cache can be populated automatically by background processes, email links, or pre-fetching, so the report must distinguish recovered cache artifacts from deliberate user navigation.
Question 18: Which EnCase evidence file format supports logical evidence collection and is commonly used for email archives?
- .E01
- .DD
- .L01 (Correct answer)
- .Ex01
Correct answer: .L01
The .L01 (Logical Evidence File) format is used in EnCase to store logical items such as email archives, specific files, or folders rather than full disk images.
Question 19: Which scenario represents a violation of the EnCase Certified Examiner code of professional conduct?
- Reporting safety concerns to regulatory authorities
- Declining work outside one's area of competence
- Misrepresenting qualifications or certification status (Correct answer)
- Seeking continuing education beyond minimum requirements
Correct answer: Misrepresenting qualifications or certification status
Misrepresenting qualifications or certification status is a serious violation of professional conduct. It undermines public trust and can lead to harm when unqualified individuals perform specialized work.
Question 20: How should findings be presented in a forensic report?
- Use complex vocabulary only
- Add speculation
- State findings clearly and objectively (Correct answer)
- Use humor
Correct answer: State findings clearly and objectively
Forensic reports must present findings clearly, concisely, and objectively, based solely on the evidence discovered and analyzed. This ensures that the report is credible, understandable to non-technical audiences, and admissible in court. It strictly avoids personal opinions, speculation, or biased language.
Question 21: What format does EnCase typically use for evidence files?
- .doc
- .E01 (Correct answer)
- .jpg
Correct answer: .E01
EnCase, a leading digital forensics tool, primarily uses the .E01 format for storing forensic images. This format, also known as EnCase Evidence File, is a proprietary but widely accepted standard that includes not only a bit-for-bit copy of the original media but also metadata, hash values, and case information. This ensures data integrity and admissibility in court.
Question 22: When examining Google Chrome's 'Top Sites' file, what format is it stored in?
- SQLite database (Correct answer)
- JSON flat file
- Binary Registry hive
- XML file
Correct answer: SQLite database
Chrome's Top Sites file is a SQLite database containing thumbnails and visit counts for the most frequently visited sites.
Question 23: What is volatile data?
- Temporary system data (Correct answer)
- Hard drive info
- Archived files
- Stored backup
Correct answer: Temporary system data
Volatile data refers to information that is temporary and exists only while a computer system is running, such as RAM contents, running processes, network connections, and logged-in users. This data is lost when the system is powered off or rebooted, making its immediate acquisition crucial in live forensic investigations.
Question 24: What is the primary reason an examiner uses a hardware write blocker when acquiring digital evidence?
- To prevent any writes to the original evidence media, preserving its forensic integrity (Correct answer)
- To speed up the imaging process by optimizing read throughput
- To compress the acquired data into an E01 container automatically
- To authenticate the examiner's credentials before allowing access to the device
Correct answer: To prevent any writes to the original evidence media, preserving its forensic integrity
A hardware write blocker sits between the examiner's workstation and the evidence device, intercepting any write commands and ensuring the original media remains bit-for-bit unaltered throughout the acquisition process.
Question 25: What documentation is MOST critical to maintain for safety compliance in the EnCase Certified Examiner field?
- Client marketing preferences
- Incident reports, training records, and inspection logs (Correct answer)
- Annual revenue reports
- Employee vacation schedules
Correct answer: Incident reports, training records, and inspection logs
Incident reports, training records, and inspection logs are essential safety documentation. They demonstrate compliance with safety regulations, track training completion, and provide evidence of systematic hazard management.
Question 26: An investigator observes large volumes of ICMP echo requests from a single internal host to external IPs. What malicious activity might this indicate?
- Man-in-the-middle attack
- ICMP tunneling or data exfiltration (Correct answer)
- ARP poisoning campaign
- SQL injection attack
Correct answer: ICMP tunneling or data exfiltration
ICMP tunneling can be used to exfiltrate data or establish covert C2 channels by embedding data within ICMP echo request/reply packets.
Question 27: Which EnCase feature allows an examiner to parse SQLite databases found on an Android device without exporting them?
- EnScript with SQLite library (Correct answer)
- Logical Evidence File viewer
- Physical Disk Emulator
- Evidence Processor
Correct answer: EnScript with SQLite library
EnScript provides a built-in SQLite library that can parse SQLite database files directly from within the case.
Question 28: An examiner finds a Windows LNK (shortcut) file on a suspect's machine. Which artifact class does this represent?
- An encrypted container for file transfer
- A prefetch entry for a deleted executable
- A Shell Link that can reveal the target's original path, volume serial number, and MAC timestamps (Correct answer)
- A file that proves the target file was executed
Correct answer: A Shell Link that can reveal the target's original path, volume serial number, and MAC timestamps
LNK files contain Shell Link Binary File Format data including target path, volume serial number, MAC address of origin machine, and timestamps — even if the target file was deleted.
Question 29: What is the PRIMARY purpose of obtaining EnCE certification in EnCase Certified Examiner?
- To guarantee employment in the field
- To bypass educational requirements
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To satisfy a personal achievement goal
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
Question 30: Which risk management approach is MOST effective for EnCE professionals when evaluating potential workplace hazards?
- Proactive hazard identification and assessment (Correct answer)
- Reactive analysis after incidents occur
- Relying solely on historical accident data
- Delegating all safety decisions to management
Correct answer: Proactive hazard identification and assessment
Proactive hazard identification and assessment allows professionals to identify and mitigate risks before incidents occur, which is far more effective than reactive approaches that only address problems after they happen.
Question 31: Which Windows artifact would help an examiner establish that a user opened a specific document stored on an external drive, even after the drive has been removed?
- Thumbcache database
- Amcache.hve
- AppCompatCache
- Recent Items LNK files with volume serial number (Correct answer)
Correct answer: Recent Items LNK files with volume serial number
LNK files in the Recent Items folder contain the volume serial number and drive letter of the source device, linking a user to a specific external drive even after removal.
Question 32: What encoding method obfuscates the program paths and GUIDs stored in the UserAssist registry key?
- Base64 encoding
- XOR with a static key
- ROT13 cipher (Correct answer)
- MD5 hashing
Correct answer: ROT13 cipher
UserAssist program paths are encoded with ROT13, a simple Caesar cipher shifting each letter by 13 positions, which is trivially reversible.
Question 33: Which EnCase feature generates an itemized list of all files examined, including deleted files, that should be referenced in the formal report?
- Bookmark report
- File list report (Correct answer)
- Case Analyzer output
- Timeline report
Correct answer: File list report
The File List report in EnCase provides an itemized inventory of all files including deleted and unallocated entries that were part of the examination scope.
Question 34: An examiner uses EnCase to analyze a mobile device and discovers the file '/data/system/locksettings.db'. What is the forensic significance of this file?
- It records GPS location data linked to lock/unlock events
- It contains a list of all installed applications and their permissions
- It holds encrypted copies of all files protected by Android's file-based encryption
- It stores the current screen lock credential type and related security settings (Correct answer)
Correct answer: It stores the current screen lock credential type and related security settings
The locksettings.db database stores the device's lock screen credential type, PIN/password hash reference, and related security configuration.
Question 35: Which feature allows users to navigate through evidence in EnCase?
- Evidence and Table view panes (Correct answer)
- Toolbar only
- Full-screen mode
- Chat window
Correct answer: Evidence and Table view panes
In EnCase, the Evidence and Table view panes are fundamental for navigating and examining digital evidence. The Evidence pane displays the hierarchical structure of the acquired data, allowing users to browse through files, folders, and partitions. The Table view pane then presents the contents of selected items in a detailed, organized format, enabling thorough analysis and review of the evidence.
Question 36: When should an examiner photograph the forensic workstation before beginning an acquisition?
- Always — to document the hardware configuration used for the acquisition (Correct answer)
- Only when imaging a RAID array
- Never — documentation begins after the image is complete
- Only when the drive shows signs of physical damage
Correct answer: Always — to document the hardware configuration used for the acquisition
Photographing the forensic workstation documents the hardware setup and write-blocker configuration, supporting the chain of custody and courtroom testimony.
Question 37: What is the PRIMARY ethical obligation of a certified EnCase Certified Examiner professional regarding confidential information?
- Use it to advance career opportunities
- Discuss it informally during professional networking
- Protect it from unauthorized disclosure at all times (Correct answer)
- Share it with colleagues who might benefit
Correct answer: Protect it from unauthorized disclosure at all times
Confidentiality is a fundamental ethical obligation. Certified professionals must protect confidential information from unauthorized disclosure, regardless of circumstances. Breach of confidentiality can result in loss of certification and legal liability.
Question 38: When examining an Ext4 Linux file system, which structure is analogous to the NTFS MFT record and stores file metadata?
- Journal block
- Inode (Correct answer)
- Block Group Descriptor
- Superblock
Correct answer: Inode
Inodes in Ext4 store file metadata (permissions, timestamps, owner, data block pointers) but do not store the filename, which is kept in directory entries.
Question 39: What is the EnScript feature used for?
- Drawing tools
- Automating forensic processes (Correct answer)
- Generating graphics
- Gaming controls
Correct answer: Automating forensic processes
EnScript is a powerful scripting language integrated within EnCase software. Its primary use is to automate complex or repetitive forensic processes, such as searching for specific file types, carving data, or generating custom reports. By leveraging EnScript, forensic examiners can significantly enhance efficiency, consistency, and thoroughness in their investigations.
Question 40: An examiner finds evidence of EnCase's EnScript automation was used to process the evidence. What should the report document about this?
- Only the final output of the EnScript
- The specific EnScript used, its version, and its purpose in the examination (Correct answer)
- EnScript runs are proprietary and need not be disclosed
- EnScripts are not admissible as part of forensic methodology
Correct answer: The specific EnScript used, its version, and its purpose in the examination
Any automated tool or script used in the examination must be documented, including its name, version, and purpose, to allow peer review and challenge of the methodology.
Question 41: What is the correct action when EnCase reports read errors (bad sectors) during a physical acquisition?
- Re-image the drive using a different acquisition tool
- Allow EnCase to log the bad sectors and continue; document the errors in the case notes (Correct answer)
- Use disk repair utilities to fix the bad sectors before continuing
- Stop the acquisition immediately and contact law enforcement
Correct answer: Allow EnCase to log the bad sectors and continue; document the errors in the case notes
EnCase logs bad sectors and pads them with zeros in the image, allowing acquisition to continue; examiners should document these errors without altering the source drive.
Question 42: Which approach best demonstrates mastery of registry analysis in EnCE practice?
- Applying principles to novel situations with sound judgment (Correct answer)
- Relying entirely on technology
- Following procedures without understanding
- Avoiding complex scenarios
Correct answer: Applying principles to novel situations with sound judgment
True mastery involves understanding underlying principles well enough to apply them to new and unfamiliar situations with professional judgment.
Question 43: Which EnCase acquisition format stores the image in multiple segments with embedded hash verification?
- EnCase Evidence File (E01) (Correct answer)
- RAW/DD format
- ISO format
- AFF format
Correct answer: EnCase Evidence File (E01)
The E01 (Expert Witness Format) stores the forensic image in compressed, segmented files with embedded CRC and MD5 hash values.
Question 44: Which principle is fundamental to good encase software practice?
- Separation of concerns and modularity (Correct answer)
- Writing as much code as possible
- Avoiding all abstraction
- Never refactoring code
Correct answer: Separation of concerns and modularity
Separation of concerns and modularity make code easier to understand, test, maintain, and extend over time.
Question 45: When conducting a risk assessment for EnCE operations, which factor should receive the HIGHEST priority?
- Probability and severity of potential harm (Correct answer)
- Cost of implementing safety measures
- Convenience for daily operations
- Time required for safety training
Correct answer: Probability and severity of potential harm
The probability and severity of potential harm are the primary factors in risk assessment. While cost and convenience are considerations, they should never override the assessment of how likely an incident is and how severe its consequences could be.
Question 46: In EnCase, the 'Conditions' feature is used to:
- Specify compression levels for E01 images
- Configure network settings for remote collections
- Set access permissions on evidence containers
- Define filter criteria to narrow down which files or records are displayed or processed (Correct answer)
Correct answer: Define filter criteria to narrow down which files or records are displayed or processed
Conditions in EnCase are saved filter definitions (e.g., file size, date range, extension) that narrow the view or processing scope to relevant items.
Question 47: What is the purpose of an 'Appendix' in a comprehensive forensic report?
- To summarize the report for non-technical readers
- To list the opposing expert's weaknesses
- To repeat the executive summary in technical language
- To provide supplementary technical data, tool outputs, and detailed tables that support but do not clutter the main narrative (Correct answer)
Correct answer: To provide supplementary technical data, tool outputs, and detailed tables that support but do not clutter the main narrative
Appendices house detailed supporting data such as full file listings, hash logs, and tool output reports that substantiate findings without disrupting the main report's readability.
Question 48: What does the Master File Table (MFT) store?
- Web history
- Wi-Fi passwords
- Battery logs
- File metadata in NTFS (Correct answer)
Correct answer: File metadata in NTFS
The Master File Table (MFT) is a fundamental component of the NTFS file system, primarily used by Windows operating systems. It functions as a comprehensive database that stores critical metadata for every file and directory on the volume. This metadata encompasses essential details like file names, sizes, timestamps, security attributes, and the physical location of the file's data on the disk.
Question 49: Which standard governs best practices for digital evidence acquisition and is referenced in many law enforcement forensic procedures?
- NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response) (Correct answer)
- ISO 27001
- PCI DSS v4.0
- COBIT 5 for Information Security
Correct answer: NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response)
NIST SP 800-86 provides guidance on integrating forensic techniques into incident response, including evidence acquisition best practices widely used by law enforcement.
Question 50: When EnCase computes an MD5 hash of an evidence file to verify integrity, this hash is stored in the:
- E01 file's header and footer segments (Correct answer)
- A separate .hash file on the network share
- Windows Registry on the examiner's workstation
- The SAFE server's audit log exclusively
Correct answer: E01 file's header and footer segments
EnCase embeds the acquisition hash within the E01 file's internal header and footer, allowing integrity verification without external files.
Question 51: What is a Device Configuration Overlay (DCO) and why is it forensically significant?
- A partition type used by Linux systems
- A write-protection mechanism built into modern drives
- A hidden drive area set by manufacturer or user that can conceal data (Correct answer)
- A BIOS setting that controls boot order
Correct answer: A hidden drive area set by manufacturer or user that can conceal data
A DCO is a drive feature that can reduce the reported drive size, hiding sectors that could contain evidence from both the OS and standard acquisition tools.
Question 52: What is the significance of the 'last_visit_time' field found in Chrome's History SQLite database for forensic purposes?
- It indicates when the browser cache entry expires
- It records the most recent timestamp a URL was visited in WebKit epoch format (Correct answer)
- It records the total number of visits to a URL
- It stores the referrer URL for the page
Correct answer: It records the most recent timestamp a URL was visited in WebKit epoch format
The last_visit_time field stores the most recent visit timestamp in WebKit time (microseconds since January 1, 1601), which examiners must convert to human-readable time.
Question 53: In EnCE practice, what is the purpose of vulnerability scanning?
- To identify weaknesses before attackers do (Correct answer)
- To exploit systems
- To slow down network traffic
- To replace firewalls
Correct answer: To identify weaknesses before attackers do
Vulnerability scanning proactively identifies security weaknesses in systems and applications so they can be remediated before exploitation.
Question 54: What role does collaboration play in internet artifacts for EnCE professionals?
- It is only needed in emergencies
- It slows down work unnecessarily
- It reduces individual accountability
- It enhances outcomes through diverse perspectives and shared expertise (Correct answer)
Correct answer: It enhances outcomes through diverse perspectives and shared expertise
Collaboration leverages diverse perspectives and combined expertise to achieve better outcomes than any individual could alone.
Question 55: What is the key to effective cross-functional communication in EnCE environments?
- Avoiding all technical details
- Using department-specific jargon
- Communicating only in writing
- Adapting language and context for different audiences (Correct answer)
Correct answer: Adapting language and context for different audiences
Adapting language and providing appropriate context for different audiences ensures effective communication across functional boundaries.
Question 56: A EnCE professional discovers a conflict of interest in a current assignment. What is the MOST ethical course of action?
- Disclose the conflict immediately and recuse if necessary (Correct answer)
- Ignore it if no one else has noticed
- Handle it privately without informing stakeholders
- Continue the assignment but document the conflict later
Correct answer: Disclose the conflict immediately and recuse if necessary
Ethical standards require immediate disclosure of conflicts of interest. Transparency protects both the professional's integrity and the stakeholders' interests. Recusal may be necessary to maintain objectivity.
Question 57: An examiner finds a USB device entry in HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR but no corresponding Windows Event Log entry. What should the examiner conclude?
- The USBSTOR registry entry must have been planted by an attacker and is unreliable
- The device was never actually used; registry entries can be created without physical connection
- Only USB devices connected in the current Windows session populate USBSTOR
- USB event logging may have been disabled or cleared, but the registry records device enumeration independently (Correct answer)
Correct answer: USB event logging may have been disabled or cleared, but the registry records device enumeration independently
USBSTOR entries are written by the Plug and Play subsystem independently of event logging; cleared or disabled logs do not invalidate the registry-based device evidence.
Question 58: Which section of a forensic report should contain the examiner's professional qualifications, certifications, and relevant experience?
- Executive summary
- Findings section
- Methodology section
- Curriculum vitae or qualifications section (Correct answer)
Correct answer: Curriculum vitae or qualifications section
The examiner's qualifications, certifications (such as EnCE), and experience are placed in a dedicated CV or qualifications section to establish their competency as an expert witness.
Question 59: During acquisition, EnCase displays 'Acquisition Verified' after computing the hash. What does this confirm?
- The write-blocker functioned correctly throughout the process
- The hash of the acquired image matches the hash computed from the source during acquisition (Correct answer)
- The image file is stored in an authenticated E01 container
- The source drive has no bad sectors
Correct answer: The hash of the acquired image matches the hash computed from the source during acquisition
Acquisition Verified confirms that the MD5/SHA-1 hash of the image file matches the hash computed from the source drive, proving the image is a faithful copy.
Question 60: In a criminal case, what is the standard of proof the prosecution must meet to secure a conviction?
- Beyond a reasonable doubt (Correct answer)
- Preponderance of the evidence
- Reasonable suspicion
- Clear and convincing evidence
Correct answer: Beyond a reasonable doubt
Criminal convictions require the prosecution to prove each element of the offense beyond a reasonable doubt, the highest legal standard.
Question 61: What must be documented in a chain of custody form?
- File size only
- Witness names
- Suspect’s hobbies
- Evidence transfer history (Correct answer)
Correct answer: Evidence transfer history
A chain of custody form is a vital legal document that meticulously tracks the handling and transfer of evidence from the moment it is collected until it is presented in court. It documents who had possession of the evidence, when, and for what purpose. This ensures its integrity and admissibility by demonstrating that it has not been tampered with.
Question 62: In EnCase, what is the 'Case Processor' primarily used for?
- Converting evidence files between E01 and Ex01 formats
- Generating final court-ready HTML reports
- Automating multiple processing tasks such as hash analysis, signature analysis, and indexing simultaneously (Correct answer)
- Synchronizing case data across multiple examiner workstations
Correct answer: Automating multiple processing tasks such as hash analysis, signature analysis, and indexing simultaneously
The EnCase Case Processor automates batch processing tasks including hash analysis, file signature analysis, index creation, and more, saving significant manual effort.
Question 63: Which approach is recommended for troubleshooting network forensics issues?
- Rely solely on past experience
- Use systematic isolation and testing methods (Correct answer)
- Wait for the problem to resolve itself
- Replace all components simultaneously
Correct answer: Use systematic isolation and testing methods
Systematic isolation and testing methodically narrows down the root cause, making troubleshooting efficient and accurate.
Question 64: In EnCase, what does examining the 'Volume Shadow Copies' (VSS) on a Windows image potentially reveal to a forensic examiner?
- Previous versions of files and system states from before deletion or modification events (Correct answer)
- A log of all user login attempts including failed passwords
- The system's BitLocker recovery keys stored in plaintext
- Metadata about all USB devices ever connected to the system
Correct answer: Previous versions of files and system states from before deletion or modification events
Volume Shadow Copies (VSS) are point-in-time snapshots of the file system created by Windows; EnCase can mount and examine these to find earlier versions of files that were subsequently deleted or modified by a subject.
Question 65: What is 'timestomping' in the context of anti-forensics, and how can EnCase help detect it?
- Deliberately altering file timestamps to mislead investigators about when files were created or accessed, detectable by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps (Correct answer)
- Embedding malware in timestamp metadata fields of JPG images
- Overwriting sectors with random data to prevent file recovery, detected by entropy analysis
- Spoofing the system clock during evidence acquisition to invalidate hash verification
Correct answer: Deliberately altering file timestamps to mislead investigators about when files were created or accessed, detectable by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps
Timestomping uses tools to modify $STANDARD_INFORMATION timestamps, but $FILE_NAME timestamps (updated only by the file system kernel) are harder to alter — discrepancies between the two in EnCase indicate potential manipulation.
Question 66: When documenting hash values in a forensic report, which algorithm is currently considered the minimum standard for evidentiary integrity verification?
- SHA-1 alone is sufficient
- MD5 alone is sufficient
- CRC32 checksum
- SHA-256 or stronger (Correct answer)
Correct answer: SHA-256 or stronger
SHA-256 or stronger is the current minimum standard because MD5 and SHA-1 are vulnerable to collision attacks that could undermine evidentiary integrity.
Question 67: What is the appropriate way to present conflicting artifact findings (e.g., a file present in MFT but absent from directory listing) in a forensic report?
- Document both findings, explain the discrepancy, and offer technically sound interpretations (Correct answer)
- Defer to the most favorable interpretation for the requesting party
- Wait until a second examiner confirms before reporting
- Report only the MFT entry and ignore the directory listing discrepancy
Correct answer: Document both findings, explain the discrepancy, and offer technically sound interpretations
Conflicting artifacts should both be documented with a technically sound explanation of why the discrepancy exists, such as anti-forensic activity or filesystem inconsistency.
Question 68: In EnCase, what does the 'Sweep Enterprise' feature enable that standard single-machine EnCase does not?
- Automated generation of Daubert-compliant reports
- Acquisition of RAM from a live system over a network
- Remote simultaneous forensic collection and triage across multiple networked endpoints (Correct answer)
- Synchronization of hash libraries across multiple forensic labs
Correct answer: Remote simultaneous forensic collection and triage across multiple networked endpoints
EnCase Endpoint Investigator (formerly Sweep Enterprise) enables remote, network-based forensic collection and analysis across many endpoints simultaneously without requiring physical access to each machine.
Question 69: What is the examiner's obligation when a peer review of the forensic report identifies a factual error before the report is submitted to court?
- Submit the original report and disclose the error verbally during testimony
- Correct the error, document the revision, and submit the corrected report with a revision history (Correct answer)
- Proceed with the original report to maintain timeline integrity
- Notify only the retaining attorney and let them decide
Correct answer: Correct the error, document the revision, and submit the corrected report with a revision history
Any identified error must be corrected before submission, and a revision history should document what changed and why to maintain transparency and professional integrity.
Question 70: What is the forensic significance of the Android 'userdata' partition in an EnCase mobile investigation?
- It stores user-installed apps, personal data, accounts, and most forensic artifacts (Correct answer)
- It exclusively stores the device's external SD card mirror
- It holds the device's radio firmware and baseband configuration
- It contains the Android OS kernel and bootloader
Correct answer: It stores user-installed apps, personal data, accounts, and most forensic artifacts
The userdata partition contains installed applications, user files, databases, credentials, and most evidentiary artifacts critical to mobile forensic investigations.
Question 71: When using EnCase's remote acquisition feature, what software must be running on the target machine?
- SAFE Authentication Server
- EnCase Examiner Desktop
- EnCase Enterprise Agent (servlet) (Correct answer)
- EnScript Daemon
Correct answer: EnCase Enterprise Agent (servlet)
The EnCase Enterprise Agent (servlet) must be deployed and running on the target endpoint to enable remote acquisition and analysis.
Question 72: When an EnCase examiner writes conclusions in a forensic report, what standard of language is most appropriate?
- Vague language to avoid being challenged on cross-examination
- Legal conclusions about guilt or innocence
- Absolute certainty statements to project confidence to the jury
- Qualified statements reflecting the weight of evidence (e.g., 'consistent with', 'indicates', 'suggests') (Correct answer)
Correct answer: Qualified statements reflecting the weight of evidence (e.g., 'consistent with', 'indicates', 'suggests')
Forensic conclusions should use qualified, evidence-based language that accurately reflects the strength of the findings without overclaiming or misrepresenting certainty.
Question 73: Which communication technique is most effective for conveying complex EnCE information?
- Using only technical jargon
- Sending lengthy emails
- Using only written memos
- Combining visual aids with clear verbal explanation (Correct answer)
Correct answer: Combining visual aids with clear verbal explanation
Combining visual aids with clear verbal explanations addresses different learning styles and improves comprehension of complex information.
Question 74: What is the primary purpose of a code of ethics in EnCE practice?
- To increase certification fees
- To complicate decision-making
- To restrict professional freedom
- To guide professional conduct and protect the public (Correct answer)
Correct answer: To guide professional conduct and protect the public
A code of ethics provides guidance for professional conduct while protecting the public from unethical practices.
Question 75: What is the MOST effective way for new EnCE professionals to build competency in their field?
- Focusing solely on the most advanced topics
- Learning entirely through trial and error
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Studying certification materials exclusively
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 76: For an EnCE examination report to withstand Daubert standard scrutiny in US federal court, the methodology section must demonstrate:
- That the methodology is testable, has known error rates, is peer-reviewed, and is generally accepted in the digital forensics community (Correct answer)
- That EnCase is commercially available software
- That the examiner has more than 10 years of experience
- That the evidence was collected by law enforcement
Correct answer: That the methodology is testable, has known error rates, is peer-reviewed, and is generally accepted in the digital forensics community
Under Daubert, expert methodology must be scientifically sound—testable with known error rates, subject to peer review, and generally accepted by the relevant scientific community.
Question 77: During a live response with EnCase, an examiner uses the 'Volatile' acquisition option. What data does this primarily capture that a traditional disk image would miss?
- Encrypted volume headers
- Running processes, open network connections, and RAM contents (Correct answer)
- File system journal entries
- Slack space and unallocated clusters
Correct answer: Running processes, open network connections, and RAM contents
Volatile data collection captures ephemeral system state — process lists, network connections, and physical memory — that exists only while the system is powered on and is lost on shutdown.
Question 78: What type of investigations is EnCase commonly used in?
- Digital forensic investigations (Correct answer)
- Real estate
- Event planning
- Interior design
Correct answer: Digital forensic investigations
EnCase is a specialized software suite designed for digital forensics. It provides comprehensive tools for acquiring, analyzing, and reporting on electronic evidence from various sources. This makes it an indispensable tool for investigations involving cybercrime, corporate espionage, and legal discovery.
Question 79: Which file path on a Windows system contains the HKEY_LOCAL_MACHINE\SYSTEM registry hive?
- C:\Users\Default\SYSTEM.reg
- C:\Windows\System32\config\SYSTEM (Correct answer)
- C:\Windows\Registry\SYSTEM.dat
- C:\Windows\SysWOW64\config\SYSTEM
Correct answer: C:\Windows\System32\config\SYSTEM
The SYSTEM hive is stored at C:\Windows\System32\config\SYSTEM on all modern Windows installations.
Question 80: What is the purpose of the Volume Shadow Copy Service (VSS) from a forensic standpoint?
- It records file hashes for integrity verification
- It manages disk quotas for user accounts
- It encrypts volumes at rest
- It creates point-in-time snapshots that may preserve deleted files and earlier file versions (Correct answer)
Correct answer: It creates point-in-time snapshots that may preserve deleted files and earlier file versions
VSS shadow copies can contain versions of files and directories from earlier points in time, allowing examiners to recover deleted content or view a system's state before evidence was destroyed.
Question 81: What is the correct way to report findings from EnCase's keyword search results in a formal forensic report?
- Report all keyword hits with context, location, and relevance determination (Correct answer)
- List only hits that support the prosecution's theory
- Only include hits verified by a second tool
- Summarize hits numerically without file locations
Correct answer: Report all keyword hits with context, location, and relevance determination
All keyword hits should be reported with their context, file location, and relevance determination to ensure completeness and avoid accusations of cherry-picking evidence.
Question 82: When documenting chain of custody for digital evidence, which element is NOT typically required?
- Description of the evidence item
- Name of person who collected the evidence
- Date and time of collection
- The monetary value of the device (Correct answer)
Correct answer: The monetary value of the device
Chain of custody documentation tracks who handled evidence and when, but the monetary value of the device is not a required chain of custody element.
Question 83: What does hashing help verify in EnCase?
- Battery life
- Compression ratio
- Data integrity (Correct answer)
- Color scheme
Correct answer: Data integrity
Hashing is a critical process in digital forensics, and in EnCase, it helps verify data integrity. A hash function generates a unique fixed-size string of characters (a hash value) for a given set of data. If even a single bit of the data changes, the hash value will be completely different, thus proving whether the evidence has been altered or remains in its original state since acquisition.
Question 84: In EnCE certification, what is the purpose of automated testing?
- To increase server costs
- To replace manual code review entirely
- To catch regressions and verify functionality continuously (Correct answer)
- To slow down development
Correct answer: To catch regressions and verify functionality continuously
Automated testing catches regressions early and verifies that functionality works as expected, providing confidence in code changes.
Question 85: Which EnCase feature allows an examiner to run custom scripts to automate the analysis of memory artifacts?
- EnCase App Central
- EnScript (Correct answer)
- EnCase SAFE
- EnCase FastBloc
Correct answer: EnScript
EnScript is EnCase's built-in scripting language and IDE that allows examiners to write custom scripts to automate evidence processing, including memory artifact analysis.
Question 86: When an EnCase examination reveals encrypted volumes that could not be accessed, how should this be reported?
- Do not mention encrypted volumes as they add no value
- List encrypted volumes only in internal notes
- State that the encrypted volumes contain illicit material
- Report the presence, size, and type of encrypted volumes and document the inability to access them as a limitation (Correct answer)
Correct answer: Report the presence, size, and type of encrypted volumes and document the inability to access them as a limitation
Inaccessible encrypted volumes must be documented in the report as a limitation, noting their presence, estimated size, and encryption type so the finding is complete and transparent.
Question 87: When analyzing a memory dump, which data structure is most useful for identifying currently running processes?
- Virtual Address Descriptor (VAD)
- EPROCESS linked list (Correct answer)
- Master File Table (MFT)
- Process Environment Block (PEB)
Correct answer: EPROCESS linked list
The EPROCESS linked list in Windows kernel memory chains all active process control blocks together, making it the primary structure for enumerating running processes.
Question 88: What is the forensic significance of the Windows Recycle Bin folder ($Recycle.Bin in Vista+) when examined in EnCase?
- It stores encrypted copies of all files opened by a user for auditing purposes
- It contains deleted files with original path and deletion timestamp metadata stored in $I files, valuable for proving user intent (Correct answer)
- It holds system restore points that can be parsed to reconstruct prior system states
- It is automatically wiped when EnCase processes the evidence image
Correct answer: It contains deleted files with original path and deletion timestamp metadata stored in $I files, valuable for proving user intent
Each deleted file in the $Recycle.Bin has a corresponding $I metadata file recording the original file path and deletion timestamp, which EnCase can parse to demonstrate user intent and file provenance.
Question 89: A forensic report discusses artifacts found in Windows Registry hives. What should the examiner clarify about Registry timestamps?
- Registry timestamps cannot be used in court
- Registry timestamps are set by EnCase and are always accurate
- Registry LastWriteTime reflects the last modification to the key but not necessarily to individual values within it (Correct answer)
- Registry key LastWriteTime is the only reliable timestamp in Windows forensics
Correct answer: Registry LastWriteTime reflects the last modification to the key but not necessarily to individual values within it
Windows Registry LastWriteTime records when the key itself was last written, but individual value modifications within that key do not update to a separate timestamp.
Question 90: What is the MOST important reason for EnCase Certified Examiner professionals to maintain continuing education?
- To increase billing rates
- To satisfy employer preferences
- To stay current with evolving standards, practices, and regulations (Correct answer)
- To accumulate credentials for personal prestige
Correct answer: To stay current with evolving standards, practices, and regulations
Continuing education ensures professionals remain current with evolving industry standards, best practices, and regulatory requirements. This directly impacts the quality of service provided and maintains public trust in the profession.
Question 91: A suspect's laptop is found running with BitLocker encryption active. What is the BEST first step for evidence acquisition?
- Immediately pull the power cord to preserve the encrypted state
- Perform a live acquisition while the system is running and decrypted (Correct answer)
- Boot from a forensic USB drive to bypass BitLocker
- Remove the drive and image it with a write-blocker
Correct answer: Perform a live acquisition while the system is running and decrypted
When BitLocker is active and the system is running in a decrypted state, live acquisition captures data in plaintext before it is re-encrypted.
Question 92: Which EnCase capability allows an examiner to view the logical file structure of a mobile device image organized by app rather than raw directory path?
- Entropy map visualization
- Hash analysis by file type
- Timeline view sorted by file extension
- Artifact view or parsed mobile report grouping data by application (Correct answer)
Correct answer: Artifact view or parsed mobile report grouping data by application
EnCase's mobile artifact reporting organizes extracted data by application category (e.g., WhatsApp, contacts, browser), making analysis more efficient.
Question 93: A report must address user attribution—proving a specific person performed actions on a computer. Which types of artifacts from EnCase provide the strongest attribution evidence?
- The IP address in DHCP logs
- The physical location of the device at time of seizure
- File creation dates alone
- A convergence of user account activity logs, typed URLs, email artifacts, and device-specific configuration files tied to the individual (Correct answer)
Correct answer: A convergence of user account activity logs, typed URLs, email artifacts, and device-specific configuration files tied to the individual
Strong user attribution requires convergent evidence—multiple artifact types that collectively point to a specific individual's account and behavioral patterns rather than any single data point.
Question 94: What documentation is MOST critical to maintain for safety compliance in the EnCase Certified Examiner field?
- Employee vacation schedules
- Incident reports, training records, and inspection logs (Correct answer)
- Client marketing preferences
- Annual revenue reports
Correct answer: Incident reports, training records, and inspection logs
Incident reports, training records, and inspection logs are essential safety documentation. They demonstrate compliance with safety regulations, track training completion, and provide evidence of systematic hazard management.
Question 95: Which EnCase feature allows an examiner to view files that have been deleted but whose directory entries still exist in an NTFS volume?
- Logical Evidence File browser
- Physical Disk view
- Hash library comparison
- Conditions filter on 'Is Deleted' (Correct answer)
Correct answer: Conditions filter on 'Is Deleted'
EnCase's Conditions filter can be set to 'Is Deleted = True' to surface files whose MFT records are marked as unallocated but retain recoverable metadata.
Question 96: When using EnCase to analyze a FAT32 volume, which structure would the examiner examine to find file entries for deleted files?
- Master File Table (MFT)
- Partition Table
- Volume Boot Record
- Directory entries with 0xE5 as the first byte (Correct answer)
Correct answer: Directory entries with 0xE5 as the first byte
In FAT32, deleted file directory entries have their first byte set to 0xE5, preserving the remaining filename and cluster chain information for potential recovery.
Question 97: A EnCE certified professional is asked to provide services outside their scope of competence. The CORRECT ethical response is to:
- Decline and refer to a qualified professional (Correct answer)
- Accept and learn as they go
- Accept the work to gain new experience
- Accept but charge a lower rate
Correct answer: Decline and refer to a qualified professional
Ethical practice requires professionals to work within their scope of competence. Accepting work beyond one's qualifications can lead to substandard results and potential harm. Referring to qualified professionals ensures proper service delivery.
Question 98: Where is the Windows hibernation file (hiberfil.sys) located on a Windows system?
- C:\Windows\Temp\
- C:\Users\<username>\
- C:\ (root of the system drive) (Correct answer)
- C:\Windows\System32\
Correct answer: C:\ (root of the system drive)
The hiberfil.sys file resides in the root of the system drive (typically C:\) and is a protected system file.
Question 99: Where does Windows store the active time zone configuration that forensic examiners must use when interpreting registry timestamps?
- HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation (Correct answer)
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DateTime
- HKCU\Software\Microsoft\Windows NT\CurrentVersion\Time Zones
Correct answer: HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation
HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation stores the active time zone bias values required to convert UTC timestamps to local system time.
Question 100: In EnCase, the 'Timeline' view assists an examiner by:
- Displaying network connection timestamps from packet captures
- Generating a Gantt chart of the examination workflow
- Showing only files created in the last 24 hours
- Plotting file system events (create, modify, access, delete) chronologically across all evidence (Correct answer)
Correct answer: Plotting file system events (create, modify, access, delete) chronologically across all evidence
The Timeline view aggregates all timestamped file system events across the evidence set and displays them in chronological order to help reconstruct activity sequences.
EnCase Certified Examiner (EnCE) Certification Exam
The EnCE certification validates a candidate's proficiency in using EnCase software for digital forensics investigations, including evidence acquisition, analysis, and reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds