EnCE EnCase Software 2 — Questions and Answers
Question 1: In EnCase, what is the purpose of the 'Evidence Processor' module?
- To encrypt evidence files before storage
- To automate tasks like file recovery, hashing, and indexing on acquired evidence (Correct answer)
- To generate court-ready PDF reports automatically
- To create logical copies of physical drives
Correct answer: To automate tasks like file recovery, hashing, and indexing on acquired evidence
The Evidence Processor automates forensic processing tasks such as hashing, file signature analysis, deleted file recovery, and index creation.
Question 2: Which EnCase view displays all files in a case in a flat, unstructured list regardless of their folder location?
- Tree pane
- Table pane in 'Home' view (Correct answer)
- File Extents view
- Records view
Correct answer: Table pane in 'Home' view
The Table pane in the Home view shows all case entries in a flat list, allowing examiners to sort and filter across all folders at once.
Question 3: What does the EnCase 'Snapshot' feature capture when run on a live system?
- A forensic image of the live drive
- Volatile system data including running processes, open ports, and logged-on users (Correct answer)
- A hash of all files on the system
- Registry hive backups
Correct answer: Volatile system data including running processes, open ports, and logged-on users
Snapshot collects volatile data from a live endpoint such as running processes, network connections, open ports, and logged-on user sessions.
Question 4: In EnCase, a 'Logical Evidence File' (L01) differs from an E01 in that it:
- Includes a bit-for-bit copy of the entire drive including slack space
- Contains only selected files and folders rather than a full physical image (Correct answer)
- Is compressed using AES-256 by default
- Cannot store hash values for verification
Correct answer: Contains only selected files and folders rather than a full physical image
An L01 is a logical container holding selected files/folders, while an E01 captures the full physical image including unallocated space and slack.
Question 5: Which EnCase feature allows an examiner to write a custom script to automate evidence analysis tasks?
- EnScript (Correct answer)
- Evidence Processor
- SAFE Query Language
- Condition Editor
Correct answer: EnScript
EnScript is EnCase's built-in programming language (C++-like) that lets examiners write custom automation scripts for evidence analysis.
Question 6: When performing a keyword search in EnCase, the 'GREP' search type allows:
- Searching only allocated file space
- Pattern-based matching using regular expressions (Correct answer)
- Searching only the index previously built by the processor
- Hashing files matching the keyword
Correct answer: Pattern-based matching using regular expressions
GREP searches in EnCase use regular expression patterns, allowing flexible pattern matching such as phone numbers, SSNs, or email formats.
Question 7: In EnCase, what is the function of the 'Bookmark' feature?
- It marks files for deletion from the evidence container
- It tags and annotates specific items or data regions for inclusion in reports (Correct answer)
- It sets the evidence file's hash verification status
- It encrypts selected files within the case
Correct answer: It tags and annotates specific items or data regions for inclusion in reports
Bookmarks allow examiners to flag, annotate, and organize key evidence items so they can be easily referenced and included in final reports.
In EnCase, what is the purpose of the 'Evidence Processor' module?