















































































Study with the several resources on Docsity
Earn points by helping other students or get them with a premium plan
Prepare for your exams
Study with the several resources on Docsity
Earn points to download
Earn points by helping other students or get them with a premium plan
This certification validates foundational skills in using NUIX for digital forensics and eDiscovery. Topics include data ingestion, indexing, searching, analytics, case management, and reporting. Candidates demonstrate operational competence in handling large-scale digital evidence sets.
Typology: Exams
1 / 87
This page cannot be seen from the preview
Don't miss anything!
















































































Question 1. Which component handles user authentication and role assignment in Nuix? A) Nuix Workstation B) Nuix Imager C) Nuix User Management Server (UMS) D) Universal Data Normalizer Answer: C Explanation: The Nuix User Management Server is responsible for managing user authentication and roles. Question 2. What is the main purpose of the Universal Data Normalizer in Nuix? A) Data encryption B) Data deduplication C) Converting diverse file types to a standard format D) Virus scanning Answer: C Explanation: The Universal Data Normalizer standardizes various data formats for consistent processing. Question 3. Which Nuix license type requires hardware dongle insertion for activation? A) Cloud license B) Server-based license C) Dongle license D) Trial license Answer: C Explanation: Dongle licenses require a physical dongle for software activation.
Question 4. During installation, which system requirement is most critical for Nuix performance? A) Monitor resolution B) CPU core count C) Printer compatibility D) USB port version Answer: B Explanation: Nuix relies on parallel processing, so more CPU cores improve performance. Question 5. What is the primary function of the Nuix Imager? A) Creating forensic disk images B) Managing user accounts C) Processing email files D) Generating hash values Answer: A Explanation: Nuix Imager is designed to create forensic copies of digital evidence. Question 6. What database option is recommended for large Nuix cases with high-speed searching? A) Derby B) Lucene C) SQLite D) MySQL Answer: B
Answer: B Explanation: Optical Character Recognition (OCR) extracts text from image files. Question 10. How does Nuix save time and storage during evidence ingestion? A) By excluding system files using pre-filtering B) By increasing worker counts C) By disabling metadata extraction D) By compressing all files Answer: A Explanation: Pre-filtering excludes irrelevant system files or date ranges to optimize resources. Question 11. What does the "Reload" feature in Nuix accomplish? A) Deletes all evidence B) Updates items with new processing settings C) Duplicates case data D) Encrypts case files Answer: B Explanation: The "Reload" feature allows reprocessing of items with updated settings. Question 12. Which Nuix interface pane displays evidence hierarchy? A) Results Pane B) Preview Pane C) Evidence Tree
D) Hash Pane Answer: C Explanation: The Evidence Tree shows how evidence is organized within a case. Question 13. Where can you view extracted text and HTML content in Nuix? A) Metadata tab B) Text/HTML tab C) Binary/Hex tab D) Case Info tab Answer: B Explanation: The Text/HTML tab shows readable content from processed files. Question 14. Which pane is best for low-level analysis of binary data? A) Results Pane B) Preview Pane C) Binary/Hex tab D) Workbench Answer: C Explanation: The Binary/Hex tab is used for examining the raw data of files. Question 15. How can Nuix interface be customized for different investigation stages? A) By changing database type B) By switching between Workbench and Reviewer views
B) Wildcard search C) Fuzzy matching D) Range search Answer: C Explanation: Fuzzy matching retrieves items with similar but not identical terms. Question 19. How can you filter evidence by creation date in Nuix? A) Using the Results Pane B) Through metadata analysis C) By exporting the case D) By changing database type Answer: B Explanation: Metadata analysis enables filtering based on file properties like creation date. Question 20. What is the primary use of regular expressions (RegEx) in Nuix? A) Encrypt files B) Find custom data patterns C) Generate case reports D) Set user permissions Answer: B Explanation: RegEx is used to search for specific, often complex data patterns. Question 21. Which named entity detection is enabled by default in Nuix?
A) Passport numbers B) Credit card numbers C) Vehicle registrations D) Bank routing numbers Answer: B Explanation: Credit card numbers are among the default named entities Nuix can identify. Question 22. What is displayed in the Map view in Nuix? A) File hash values B) Geographical data C) Database size D) User login history Answer: B Explanation: The Map view visualizes geographical information extracted from evidence. Question 23. Which Windows artifact files represent deleted items in the Recycle Bin? A) $S files B) $I and $R files C) $D files D) $B files Answer: B Explanation: $I and $R files correspond to deleted items and their metadata in the Recycle Bin.
Question 27. Mobile extractions in Nuix often come from which forensic tool format? A) UFDR B) PST C) E D) ZIP Answer: A Explanation: UFDR files are typically generated by Cellebrite for mobile forensics. Question 28. How does Nuix synchronize mobile artifacts with computer-based evidence? A) By importing UFDR/XRY files and merging case items B) By hashing all files C) By manually editing metadata D) By exporting all evidence Answer: A Explanation: Mobile artifacts are imported and correlated with computer evidence for a unified view. Question 29. Which Nuix license model is ideal for organizations with multiple investigators? A) Single-user dongle license B) Cloud/server-based license C) Trial license D) Demo license Answer: B
Explanation: Cloud/server-based licenses allow for centralized management and multiple users. Question 30. What is the primary benefit of Nuix's patented parallel processing engine? A) Increased database size B) Faster evidence processing C) Enhanced user interface D) Improved OCR accuracy Answer: B Explanation: Parallel processing distributes workloads for faster analysis. Question 31. Which evidence type requires Nuix to perform email threading during processing? A) PST files B) Image files C) Video files D) Registry hives Answer: A Explanation: Email threading is used to organize related messages within PST files. Question 32. What does the Derby database offer in Nuix case management? A) Fast searching for large cases B) Lightweight storage for small cases C) Enhanced OCR capabilities D) Mobile artifact support
D) Improves OCR speed Answer: B Explanation: Data culling excludes unnecessary files, saving time and storage. Question 36. Which tab in the Preview Pane allows investigators to see file metadata? A) Binary/Hex B) Results C) Metadata D) Text/HTML Answer: C Explanation: The Metadata tab displays system and application details about the file. Question 37. What type of search would you use to find all files with ".docx" extension in Nuix? A) Boolean search B) Wildcard search C) Proximity search D) Fuzzy search Answer: B Explanation: Wildcard searches can locate files matching patterns like "*.docx". Question 38. In Nuix, how is evidence ingestion performance optimized? A) By increasing worker count B) By disabling all filters
C) By lowering CPU frequency D) By using Derby database only Answer: A Explanation: More workers allow parallel processing for faster ingestion. Question 39. Which forensic image format is supported for disk evidence in Nuix? A) MP B) E C) PDF D) DOCX Answer: B Explanation: E01 is a standard forensic image format supported by Nuix. Question 40. What is the function of the Results Pane in Nuix? A) Display evidence hierarchy B) Show search results and item details C) Manage licenses D) Perform OCR Answer: B Explanation: The Results Pane presents filtered evidence, search results, and item details. Question 41. Which Nuix feature visualizes communication flows between individuals? A) Map view
A) Importing UFDR or XRY files B) Running file carving C) Exporting to PST D) Disabling OCR Answer: A Explanation: Mobile extractions are typically imported from UFDR or XRY files. Question 45. Which database option is recommended when case size exceeds 10 million items? A) Derby B) Lucene C) SQLite D) SQL Server Answer: B Explanation: Lucene is designed for scalability and fast performance with large cases. Question 46. How can you troubleshoot a failed Nuix installation? A) Check hardware requirements and install logs B) Disable antivirus software C) Delete all licenses D) Increase case size Answer: A Explanation: Reviewing system requirements and installation logs helps identify issues.
Question 47. In Nuix, how are duplicate files identified? A) By file extension B) By comparing hash values C) By file size only D) By user account Answer: B Explanation: Hash values (MD5/SHA-1) are used to find duplicate files. Question 48. What does the "Preview Pane" enable in Nuix? A) License management B) File content preview and analysis C) Worker assignment D) Database selection Answer: B Explanation: The Preview Pane allows viewing and analyzing file contents and metadata. Question 49. How does Nuix handle password-protected evidence files? A) Skips them by default B) Attempts password cracking if enabled C) Deletes them D) Converts them to plain text Answer: B Explanation: Nuix can attempt to unlock password-protected files with the right settings.
Explanation: Wildcard searches broaden results to include variations of search terms. Question 53. Which Nuix setting should be enabled to extract text from PDFs with embedded images? A) MD5 hashing B) OCR C) Email threading D) File carving Answer: B Explanation: OCR extracts text from image-based PDF documents. Question 54. What is the main consequence of insufficient worker assignment in Nuix processing? A) Slower evidence ingestion B) Larger database size C) More duplicate files D) Increased OCR accuracy Answer: A Explanation: Fewer workers result in slower parallel processing. Question 55. How does Nuix identify email addresses within evidence? A) Named entity detection B) File extension analysis C) Manual review only D) Hash comparison
Answer: A Explanation: Named entity detection automates the identification of email addresses. Question 56. Where can you view the structure of imported mobile evidence in Nuix? A) Evidence Tree B) Results Pane C) Map View D) License Manager Answer: A Explanation: The Evidence Tree shows the hierarchy of all imported evidence, including mobile data. Question 57. What is the purpose of MD5/SHA-1 hashing during processing? A) Compress files B) Generate unique identifiers C) Increase evidence volume D) Reduce CPU usage Answer: B Explanation: Hashing creates unique identifiers for evidence verification and deduplication. Question 58. Which Nuix component allows for managing user permissions? A) Nuix Imager B) Nuix User Management Server (UMS) C) Evidence Tree