Which statement about a forensic tool's capability is true?

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

Which statement about a forensic tool's capability is true?

Explanation:
NTFS stores file metadata in the Master File Table, and there’s often data lingering in slack space—the unused portion of a cluster after a file has been written. A capable forensic tool like EnCase can search both the MFT and slack space to locate evidence and recover files, including those that have been deleted or partially overwritten. This dual capability is what makes the statement true: it isn’t limited to one area but can systematically examine key NTFS structures to reconstruct or retrieve data. The other options misstate EnCase’s scope, such as claiming it can only search MFT, that it cannot search slack space, or that its primary focus is registry analysis, which isn’t its main role in most investigations.

NTFS stores file metadata in the Master File Table, and there’s often data lingering in slack space—the unused portion of a cluster after a file has been written. A capable forensic tool like EnCase can search both the MFT and slack space to locate evidence and recover files, including those that have been deleted or partially overwritten. This dual capability is what makes the statement true: it isn’t limited to one area but can systematically examine key NTFS structures to reconstruct or retrieve data. The other options misstate EnCase’s scope, such as claiming it can only search MFT, that it cannot search slack space, or that its primary focus is registry analysis, which isn’t its main role in most investigations.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy