EnCE EnCase Software 3 — Questions and Answers
Question 1: What is the EnCase 'Safe' (SAFE) server primarily used for in enterprise deployments?
- Storing encrypted backups of evidence files
- Centrally managing cases, users, roles, and remote collection across endpoints (Correct answer)
- Running EnScript modules in the cloud
- Generating automated court reports
Correct answer: Centrally managing cases, users, roles, and remote collection across endpoints
The SAFE (Secure Authentication for EnCase) server provides centralized case management, user authentication, role-based access control, and remote agent coordination.
Question 2: In EnCase, 'file signature analysis' compares a file's header bytes against its extension to:
- Recover deleted files from unallocated space
- Detect files whose true type does not match their extension, indicating possible hiding (Correct answer)
- Generate MD5 hashes for all files
- Identify encrypted file containers
Correct answer: Detect files whose true type does not match their extension, indicating possible hiding
File signature analysis identifies mismatches between a file's magic bytes (true type) and its extension, which may indicate deliberate obfuscation.
Question 3: Which of the following best describes EnCase's 'Sweep Enterprise' capability?
- It physically wipes drives across a network
- It simultaneously searches multiple remote endpoints for specified artifacts or conditions (Correct answer)
- It creates full forensic images of all endpoints on a subnet
- It schedules automatic Evidence Processor runs on collected evidence
Correct answer: It simultaneously searches multiple remote endpoints for specified artifacts or conditions
Sweep Enterprise allows an examiner to push queries or conditions to multiple networked endpoints simultaneously, collecting targeted data at scale.
Question 4: In EnCase, what is stored in the 'case file' (.case extension)?
- The raw forensic image data
- Metadata about the case including evidence paths, bookmarks, tags, and search results (Correct answer)
- Encrypted copies of all examined files
- The EnScript source code used during examination
Correct answer: Metadata about the case including evidence paths, bookmarks, tags, and search results
The .case file is a metadata container storing case configuration, evidence references, bookmarks, tags, and analysis results — not the actual evidence data.
Question 5: When EnCase computes an MD5 hash of an evidence file to verify integrity, this hash is stored in the:
- Windows Registry on the examiner's workstation
- E01 file's header and footer segments (Correct answer)
- A separate .hash file on the network share
- The SAFE server's audit log exclusively
Correct answer: E01 file's header and footer segments
EnCase embeds the acquisition hash within the E01 file's internal header and footer, allowing integrity verification without external files.
Question 6: In EnCase, the 'Conditions' feature is used to:
- Set access permissions on evidence containers
- Define filter criteria to narrow down which files or records are displayed or processed (Correct answer)
- Configure network settings for remote collections
- Specify compression levels for E01 images
Correct answer: Define filter criteria to narrow down which files or records are displayed or processed
Conditions in EnCase are saved filter definitions (e.g., file size, date range, extension) that narrow the view or processing scope to relevant items.
Question 7: Which feature in EnCase allows an examiner to view the raw hexadecimal content of any file or disk sector?
- Report view
- Hex view (Disk/File pane) (Correct answer)
- Table view
- Timeline view
Correct answer: Hex view (Disk/File pane)
The Hex view pane in EnCase displays the raw hexadecimal and ASCII representation of any selected file, sector, or memory region.
What is the EnCase 'Safe' (SAFE) server primarily used for in enterprise deployments?