CHFI OS and File System Forensics • 20 Questions
20 CHFI OS and File System Forensics practice questions with answers and explanations. Free, no signup.
During a forensic investigation of a compromised Linux server, an investigator needs to recover deleted files from an ext4 filesystem. Which method should the investigator use to maximize recovery of file content, considering the filesystem may have been partially overwritten?