CHFI OS and File System Forensics • 20 Questions
20 CHFI OS and File System Forensics practice questions with answers and explanations. Free, no signup.
During a forensic investigation of a compromised Linux server, an investigator needs to recover deleted files from an ext4 filesystem. Which method should the investigator use to maximize recovery of file content, considering the filesystem may have been partially overwritten?
Choose an answer to begin — your selection is scored in the full session.
10 questions · instant feedback and full explanations after every question.