Labour Day Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 2493360325

Good News !!! GD0-100 Certification Exam For ENCE North America is now Stable and With Pass Result

GD0-100 Practice Exam Questions and Answers

Certification Exam For ENCE North America

Last Update 3 days ago
Total Questions : 176

GD0-100 is stable now with all latest exam questions are added 3 days ago. Just download our Full package and start your journey with Guidance Software Certification Exam For ENCE North America certification. All these Guidance Software GD0-100 practice exam questions are real and verified by our Experts in the related industry fields.

GD0-100 PDF

GD0-100 PDF (Printable)
$48
$119.99

GD0-100 Testing Engine

GD0-100 PDF (Printable)
$56
$139.99

GD0-100 PDF + Testing Engine

GD0-100 PDF (Printable)
$70.8
$176.99
Question # 1

You are examining a hard drive that has Windows XP installed as the operating system. You see a file that has a date and time in the deleted column. Where does that date and time come from?

Options:

A.  

Directory Entry

B.  

Master File Table

C.  

Info2 file

D.  

Inode Table

Discussion 0
Question # 2

Hash libraries are commonly used to:

Options:

A.  

Compare a file header to a file extension.

B.  

Identify files that are already known to the user.

C.  

Compare one hash set with another hash set.

D.  

Verify the evidence file.

Discussion 0
Question # 3

By default, EnCase will display the data from the end of a logical file, to the end of the cluster, in what color:

Options:

A.  

Red

B.  

Red on black

C.  

Black on red

D.  

Black

Discussion 0
Question # 4

The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result.[\x00-\x05]\x00\x00?>[?[@?[?[?[

Options:

A.  

FF 0000 00 00 FF BA

B.  

0000 00 01 FF FF BA

C.  

04 06 0000 00 FF FF BA

D.  

04 0000 00 FF FF BA

Discussion 0
Question # 5

To undelete a file in the FAT file system, EnCase computes the number of _______ the file will use based on the file ______.

Options:

A.  

Clusters;starting extent

B.  

Sectors;starting extent

C.  

Clusters;file size

D.  

Sectors;file size

Discussion 0
Question # 6

Search terms are case sensitive by default.

Options:

A.  

False

B.  

True

Discussion 0
Question # 7

A SCSI drive is pinned as a master when it is:

Options:

A.  

The only drive on the computer.

B.  

The primary of two drives connected to one cable.

C.  

Whenever another drive is on the same cable and is pinned as a slave.

D.  

A SCSI drive is not pinned as a master.

Discussion 0
Question # 8

If cluster #3552 entry in the FAT table contains a value of ?? this would mean:

Options:

A.  

The cluster is unallocated

B.  

The cluster is the end of a file

C.  

The cluster is allocated

D.  

The cluster is marked bad

Discussion 0
Question # 9

When does the POST operation occur?

Options:

A.  

When SCSI devices are configured.

B.  

When Windows starts up.

C.  

After a computer begins to boot from a device.

D.  

When the power button to a computer is turnedon.

Discussion 0
Question # 10

You are assigned to assist with the search and seizure of several computers. The magistrate ordered that the computers cannot be seized unless they are found to contain any one of ten previously identified images. You currently have the ten images in JPG format. Using the EnCase methodology, how would you best handle this situation?

Options:

A.  

UseFastBloc or a network/parallel port cable to preview the hard drives. Go to the Gallery view and search for the previously identified images.

B.  

UseFastBloc or a network/parallel port cable to acquire forensic images of the hard drives, then search the evidence files for the previously identified images.

C.  

UseFastBloc or a network/parallel port cable to preview the hard drives. Conduct a hash analysis of the files on the hard drives, using a hash library containing the hash values of the previously identified images.

D.  

Use an EnCase DOS boot disk to conduct a text search for child porn. Use an EnCase DOS boot disk to conduct a text search for child porn?

Discussion 0
Question # 11

When an EnCase user double-clicks on a valid .jpg file, that file is:

Options:

A.  

Copied to the default export folder and opened by an associated program.

B.  

Renamed to JPG_0001.jpg and copied to the default export folder.

C.  

Copied to the EnCase specified temp folder and opened by an associated program.

D.  

Opened by EnCase.

Discussion 0
Question # 12

A restored floppy diskette will have the same hash value as the original diskette.

Options:

A.  

True

B.  

False

Discussion 0
Question # 13

A case file can contain ____ hard drive images?

Options:

A.  

5

B.  

1

C.  

any number of

D.  

10

Discussion 0
Question # 14

Within EnCase, clicking on Save on the toolbar affects what file(s)?

Options:

A.  

All of the above

B.  

The evidence files

C.  

The open case file

D.  

The configuration .ini files

Discussion 0
Question # 15

You are working in a computer forensic lab. A law enforcement investigator brings you a computer and a valid search warrant. You have legal authority to search the computer. The investigator hands you a piece of paper that has three printed checks on it. All three checks have the same check and account number. You image the suspect computer and open the evidence file with EnCase. You checks have the same check and account number. You image the suspect's computer and open the evidence file with EnCase. You perform a text search for the account number and check number. Nothing returns on the search results. You perform a text search for all other information found on the printed checks and there is still nothing returned in the search results. You run a signature analysis and check the gallery. You cannot locate any graphical copies of the printed checks in the gallery. At this point, is it safe to say that the checks are not located on the suspect computer?

Options:

A.  

No. The images could be located a compressed file.

B.  

No. The images could be embedded in a document.

C.  

No. The images could be in unallocated clusters.

D.  

No. The images could be in an image format not viewable inside EnCase.

E.  

All of the above.

Discussion 0
Question # 16

A sector on a floppy disk is the same size as a sector on a NTFS formatted hard drive.

Options:

A.  

False

B.  

True

Discussion 0
Question # 17

When a file is deleted in the FAT file system, what happens to the FAT?

Options:

A.  

The FAT entries for that file are marked as allocated.

B.  

Nothing.

C.  

It is deleted as well.

D.  

The FAT entries for that file are marked as available.

Discussion 0
Question # 18

The following GREP expression was typed in exactly as shown. Choose the answer(s) that would result. 800[) \-]+555-1212

Options:

A.  

(800) 555-1212

B.  

800-555 1212

C.  

8005551212

D.  

800.555.1212

Discussion 0
Question # 19

An evidence file can be moved to another directory without changing the file verification.

Options:

A.  

False

B.  

True

Discussion 0
Question # 20

When Unicode is selected for a search keyword, EnCase:

Options:

A.  

Will find the keyword if it is either Unicode or ASCII.

B.  

Unicode is not a search option for EnCase.

C.  

Will only find the keyword if it is Unicode.

D.  

None of the above.

Discussion 0
Question # 21

By default, what color does EnCase use for slack?

Options:

A.  

Black on red

B.  

Red on black

C.  

Red

D.  

Black

Discussion 0
Question # 22

The following keyword was typed in exactly as shown. Choose the answer(s) that would result. All search criteria have default settings. credit card

Options:

A.  

Card

B.  

Credit Card

C.  

credit card

D.  

Credit

Discussion 0
Question # 23

Select the appropriate name for the highlighted area of the binary numbers.

Options:

A.  

Byte

B.  

Dword

C.  

Word

D.  

Bit

E.  

Nibble

Discussion 0
Question # 24

When an EnCase user double-clicks on a file within EnCase what determines the action that will result? Select all that apply

Options:

A.  

The settings in the case file.

B.  

The settings in the FileTypes.ini file.

C.  

The setting in the evidence file.

Discussion 0
Question # 25

Search terms are stored in what .ini configuration file

Options:

A.  

FileSignatures.ini

B.  

Keywords.ini

C.  

TextStyle.ini

D.  

FileTypes.ini

Discussion 0
Question # 26

When a drive letter is assigned to a logical volume, that information is temporarily written the volume boot record on the hard drive.

Options:

A.  

True

B.  

False

Discussion 0
Get GD0-100 dumps and pass your exam in 24 hours!

Free Exams Sample Questions