EnCE Evidence Acquisition & Preservation 3 — Questions and Answers
Question 1: An examiner needs to acquire a drive that is larger than the destination media. What is the best approach?
- Skip unallocated space to reduce image size
- Use compression in EnCase to reduce the image size
- Use multiple destination drives with segmented image files (Correct answer)
- Acquire only the active partitions
Correct answer: Use multiple destination drives with segmented image files
EnCase supports spanning a forensic image across multiple destination drives using segmented E01 files when the source exceeds destination capacity.
Question 2: Which hashing algorithm does EnCase use by default for evidence verification in modern versions?
- MD5 only
- SHA-1 only
- MD5 and SHA-1 simultaneously (Correct answer)
- SHA-256 only
Correct answer: MD5 and SHA-1 simultaneously
Modern EnCase versions compute both MD5 and SHA-1 hash values simultaneously during acquisition for dual verification.
Question 3: What does 'sector-by-sector' acquisition capture that a logical acquisition does NOT?
- Encrypted files
- Active partition tables
- Deleted files and unallocated space (Correct answer)
- File system journal entries
Correct answer: Deleted files and unallocated space
Sector-by-sector (physical) acquisition captures every sector including deleted files and unallocated space, which logical acquisition skips.
Question 4: In EnCase, what is the function of the 'Acquisition Notes' field when creating a forensic image?
- To store the hash value of the image
- To record examiner observations and case metadata embedded in the E01 header (Correct answer)
- To specify the compression level used
- To define the target path for the image file
Correct answer: To record examiner observations and case metadata embedded in the E01 header
Acquisition notes are embedded in the E01 header and allow the examiner to document case number, examiner name, and other metadata directly in the image file.
Question 5: A suspect's laptop is found running with BitLocker encryption active. What is the BEST first step for evidence acquisition?
- Immediately pull the power cord to preserve the encrypted state
- Perform a live acquisition while the system is running and decrypted (Correct answer)
- Remove the drive and image it with a write-blocker
- Boot from a forensic USB drive to bypass BitLocker
Correct answer: Perform a live acquisition while the system is running and decrypted
When BitLocker is active and the system is running in a decrypted state, live acquisition captures data in plaintext before it is re-encrypted.
Question 6: What is the purpose of imaging a drive's Host Protected Area (HPA)?
- To recover deleted files from the file system
- To capture potentially hidden data that the OS cannot normally access (Correct answer)
- To verify the drive's S.M.A.R.T. data
- To acquire the drive's firmware partition
Correct answer: To capture potentially hidden data that the OS cannot normally access
The HPA is a portion of the drive hidden from the operating system; imaging it can reveal data intentionally concealed by suspects.
Question 7: When should an examiner photograph the forensic workstation before beginning an acquisition?
- Only when imaging a RAID array
- Always — to document the hardware configuration used for the acquisition (Correct answer)
- Only when the drive shows signs of physical damage
- Never — documentation begins after the image is complete
Correct answer: Always — to document the hardware configuration used for the acquisition
Photographing the forensic workstation documents the hardware setup and write-blocker configuration, supporting the chain of custody and courtroom testimony.
An examiner needs to acquire a drive that is larger than the destination media.
What is the best approach?