What information should be obtained from the BIOS during computer forensic investigations?
All investigators using EnCase should run tests on the evidence file acquisition and verification process to:
Assume that an evidence file is added to a case, the case is saved, and the case is closed. What happens if the evidence file is moved, and the case is then opened?