EnCE EnCase Software 5 — Questions and Answers
Question 1: In EnCase, which report element can an examiner include to show the exact byte offset of a piece of evidence within the forensic image?
- File signature summary
- Bookmark with sector/offset annotation (Correct answer)
- Hash library comparison table
- Condition filter export
Correct answer: Bookmark with sector/offset annotation
Bookmarks in EnCase can include the precise sector and byte offset of flagged data, providing verifiable evidence location for court documentation.
Question 2: What is the purpose of EnCase's 'Index Search' compared to a raw keyword search?
- Index Search is more thorough because it scans every bit of the image
- Index Search is faster because it queries a pre-built word index rather than scanning raw data (Correct answer)
- Index Search only works on allocated file space
- Index Search ignores Unicode characters
Correct answer: Index Search is faster because it queries a pre-built word index rather than scanning raw data
Index Search queries the pre-built index created by the Evidence Processor, making it significantly faster than scanning raw bytes — though it only finds indexed terms.
Question 3: An examiner using EnCase notices a file's logical size is 1 KB but its physical size shows 4 KB. This difference represents:
- Compression applied by the file system
- File slack — the unused space at the end of the last allocated cluster (Correct answer)
- An error in the EnCase acquisition
- Alternate data stream content
Correct answer: File slack — the unused space at the end of the last allocated cluster
The gap between logical size (actual file content) and physical size (allocated cluster space) is file slack, which can contain residual data from prior files.
Question 4: In EnCase, NTFS Alternate Data Streams (ADS) are significant in forensics because they:
- Always appear in Windows Explorer and standard directory listings
- Can hide data attached to a file without being visible through normal OS tools (Correct answer)
- Are automatically deleted when the primary file is copied
- Cannot be parsed by EnCase's file system parser
Correct answer: Can hide data attached to a file without being visible through normal OS tools
ADS allows additional data streams to be attached to NTFS files; they are invisible in standard directory listings, making them a common data-hiding technique.
Question 5: When EnCase displays a 'Protected' status for a file during evidence processing, it typically indicates:
- The file is encrypted or password-protected and could not be fully parsed (Correct answer)
- The file is marked read-only in the file system
- EnCase has applied evidence-container encryption to the file
- The SAFE server denied access to the file
Correct answer: The file is encrypted or password-protected and could not be fully parsed
A 'Protected' file status in EnCase indicates the file is encrypted, password-protected, or otherwise inaccessible to normal parsing by the processor.
Question 6: In EnCase, the 'Timeline' view assists an examiner by:
- Showing only files created in the last 24 hours
- Plotting file system events (create, modify, access, delete) chronologically across all evidence (Correct answer)
- Displaying network connection timestamps from packet captures
- Generating a Gantt chart of the examination workflow
Correct answer: Plotting file system events (create, modify, access, delete) chronologically across all evidence
The Timeline view aggregates all timestamped file system events across the evidence set and displays them in chronological order to help reconstruct activity sequences.
Question 7: Which EnCase feature allows a forensic examiner to query and parse Windows Registry hives directly from a forensic image?
- EnCase Registry Viewer (built-in artifact parser) (Correct answer)
- The Snapshot module (live-only)
- EnScript Registry API
- An external third-party plugin only
Correct answer: EnCase Registry Viewer (built-in artifact parser)
EnCase includes a built-in Registry Viewer artifact parser that can read and display Windows Registry hives from a forensic image without booting the OS.
In EnCase, which report element can an examiner include to show the exact byte offset of a piece of evidence within the forensic image?