EnCE Report Writing 4 — Questions and Answers
Question 1: When an EnCase examination reveals encrypted volumes that could not be accessed, how should this be reported?
- Do not mention encrypted volumes as they add no value
- Report the presence, size, and type of encrypted volumes and document the inability to access them as a limitation (Correct answer)
- State that the encrypted volumes contain illicit material
- List encrypted volumes only in internal notes
Correct answer: Report the presence, size, and type of encrypted volumes and document the inability to access them as a limitation
Inaccessible encrypted volumes must be documented in the report as a limitation, noting their presence, estimated size, and encryption type so the finding is complete and transparent.
Question 2: An examiner finds evidence of EnCase's EnScript automation was used to process the evidence. What should the report document about this?
- EnScript runs are proprietary and need not be disclosed
- The specific EnScript used, its version, and its purpose in the examination (Correct answer)
- Only the final output of the EnScript
- EnScripts are not admissible as part of forensic methodology
Correct answer: The specific EnScript used, its version, and its purpose in the examination
Any automated tool or script used in the examination must be documented, including its name, version, and purpose, to allow peer review and challenge of the methodology.
Question 3: What is the appropriate way to present conflicting artifact findings (e.g., a file present in MFT but absent from directory listing) in a forensic report?
- Report only the MFT entry and ignore the directory listing discrepancy
- Document both findings, explain the discrepancy, and offer technically sound interpretations (Correct answer)
- Defer to the most favorable interpretation for the requesting party
- Wait until a second examiner confirms before reporting
Correct answer: Document both findings, explain the discrepancy, and offer technically sound interpretations
Conflicting artifacts should both be documented with a technically sound explanation of why the discrepancy exists, such as anti-forensic activity or filesystem inconsistency.
Question 4: A forensic report references an email extracted using EnCase. Which metadata fields are most critical to include for evidentiary completeness?
- Only the email body text
- Sender, recipient, timestamp, message-ID, and path to the evidence container (Correct answer)
- Subject line and attachment names only
- The email client version and operating system
Correct answer: Sender, recipient, timestamp, message-ID, and path to the evidence container
Complete email documentation requires sender, recipient, timestamp, message-ID for authenticity, and the precise path within the forensic image where the artifact was located.
Question 5: When an EnCase examiner writes conclusions in a forensic report, what standard of language is most appropriate?
- Absolute certainty statements to project confidence to the jury
- Qualified statements reflecting the weight of evidence (e.g., 'consistent with', 'indicates', 'suggests') (Correct answer)
- Vague language to avoid being challenged on cross-examination
- Legal conclusions about guilt or innocence
Correct answer: Qualified statements reflecting the weight of evidence (e.g., 'consistent with', 'indicates', 'suggests')
Forensic conclusions should use qualified, evidence-based language that accurately reflects the strength of the findings without overclaiming or misrepresenting certainty.
Question 6: What is the purpose of an 'Appendix' in a comprehensive forensic report?
- To summarize the report for non-technical readers
- To provide supplementary technical data, tool outputs, and detailed tables that support but do not clutter the main narrative (Correct answer)
- To list the opposing expert's weaknesses
- To repeat the executive summary in technical language
Correct answer: To provide supplementary technical data, tool outputs, and detailed tables that support but do not clutter the main narrative
Appendices house detailed supporting data such as full file listings, hash logs, and tool output reports that substantiate findings without disrupting the main report's readability.
Question 7: An examiner must report on LNK (Windows shortcut) files found during an EnCase examination. What critical forensic value do LNK file timestamps provide?
- They prove a suspect opened a specific file at a specific time with absolute certainty
- They can indicate when a linked file was last accessed on the system, providing usage timeline evidence (Correct answer)
- They are unreliable and should never be included in forensic reports
- They only reflect when the shortcut itself was created, not when it was used
Correct answer: They can indicate when a linked file was last accessed on the system, providing usage timeline evidence
LNK files contain MAC timestamps that can indicate when the linked target file was accessed, making them valuable for establishing a timeline of file usage activity.
When an EnCase examination reveals encrypted volumes that could not be accessed, how should this be reported?