Book description
The official, Guidance Software-approved book on the newest EnCE exam!
The EnCE exam tests that computer forensic analysts and examiners have thoroughly mastered computer investigation methodologies, as well as the use of Guidance Software's EnCase Forensic 7. The only official Guidance-endorsed study guide on the topic, this book prepares you for the exam with extensive coverage of all exam topics, real-world scenarios, hands-on exercises, up-to-date legal information, and sample evidence files, flashcards, and more.
Guides readers through preparation for the newest EnCase Certified Examiner (EnCE) exam
Prepares candidates for both Phase 1 and Phase 2 of the exam, as well as for practical use of the certification
Covers identifying and searching hardware and files systems, handling evidence on the scene, and acquiring digital evidence using EnCase Forensic 7
Includes hands-on exercises, practice questions, and up-to-date legal information
Sample evidence files, Sybex Test Engine, electronic flashcards, and more
If you're preparing for the new EnCE exam, this is the study guide you need.
Table of contents
- Cover
- Acknowledgments
- About the Author
- Introduction
- Chapter 1: Computer Hardware
- Chapter 2: File Systems
- Chapter 3: First Response
-
Chapter 4: Acquiring Digital Evidence
- Creating EnCase Forensic Boot Disks
- Booting a Computer Using the EnCase Boot Disk
- Drive-to-Drive DOS Acquisition
- Network Acquisitions
- FastBloc/Tableau Acquisitions
- FastBloc SE Acquisitions
- LinEn Acquisitions
- Enterprise and FIM Acquisitions
- EnCase Portable
- Helpful Hints
- Summary
- Exam Essentials
- Review Questions
- Chapter 5: EnCase Concepts
- Chapter 6: EnCase Environment
- Chapter 7: Understanding, Searching For, and Bookmarking Data
- Chapter 8: File Signature Analysis and Hash Analysis
-
Chapter 9: Windows Operating System Artifacts
- Dates and Times
- Recycle Bin
- Link Files
- Windows Folders
- Recent Folder
- Desktop Folder
- My Documents/Documents
- Send To Folder
- Temp Folder
- Favorites Folder
- Windows Vista Low Folders
- Cookies Folder
- History Folder
- Temporary Internet Files
- Swap File
- Hibernation File
- Print Spooling
- Legacy Operating System Artifacts
- Windows Volume Shadow Copy
- Windows Event Logs
- Summary
- Exam Essentials
- Review Questions
- Chapter 10: Advanced EnCase
-
Appendix A: Answers to Review Questions
- Chapter 1: Computer Hardware
- Chapter 2: File Systems
- Chapter 3: First Response
- Chapter 4: Acquiring Digital Evidence
- Chapter 5: EnCase Concepts
- Chapter 6: EnCase Environment
- Chapter 7: Understanding, Searching For, and Bookmarking Data
- Chapter 8: File Signature Analysis and Hash Analysis
- Chapter 9: Windows Operating System Artifacts
- Chapter 10: Advanced EnCase
- Appendix B: Creating Paperless Reports
- Appendix C: About the Additional Study Tools
- Index
- Advertisement
Product information
- Title: EnCE EnCase Computer Forensics: The Official EnCase Certified Examiner Study Guide, 3rd Edition
- Author(s):
- Release date: September 2012
- Publisher(s): Sybex
- ISBN: 9780470901069
You might also like
book
Handbook of Digital Forensics and Investigation
This completely revised reference work will concentrate on providing specific practical information in a well organized …
book
System Forensics, Investigation, and Response, 3rd Edition
Part of the Jones & Bartlett Learning Information Systems Security & Assurance Series! System Forensics, Investigation, …
book
Investigating the Cyber Breach: The Digital Forensics Guide for the Network Engineer, First Edition
Investigating the Cyber Breach The Digital Forensics Guide for the Network Engineer Understand the realities of …
book
Cyber Security and Digital Forensics
CYBER SECURITY AND DIGITAL FORENSICS Cyber security is an incredibly important issue that is constantly changing, …