20+ practice questions focused on Storage Forensics and File System Analysis — one of the most tested topics on the Computer Hacking Forensic Investigator CHFI exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Storage Forensics and File System Analysis PracticeAn investigator uses FTK Imager to capture a forensic image of a suspect's hard drive. During acquisition, the tool reports that the DCO (Device Configuration Overlay) is present. What does this indicate?
Explanation: The Device Configuration Overlay (DCO) is a reserved area on a hard drive that can be used to hide data from the operating system and standard forensic tools. Its presence during acquisition with FTK Imager indicates that the drive may have been deliberately tampered with to conceal data, as the DCO can be created or modified to store information outside the normally accessible user area.
Which THREE of the following are file systems that use journaling to maintain integrity?
Explanation: NTFS (A) is correct because it is a journaling file system that records metadata transactions in the $LogFile ($LogFile metadata file) so that the volume can be recovered to a consistent state after a crash. ext4 (C) is correct because it is a journaling file system that uses the JBD2 (Journaling Block Device 2) layer to journal metadata (and optionally data) operations, ensuring file system integrity after an unclean shutdown. HFS+ (D) is correct because it is a journaling file system that maintains a journal to protect the catalog and other metadata structures, allowing fast recovery and consistency checks. FAT32 (B) is not correct because it is a non-journaling file system that relies on FAT table copies and consistency-check tools rather than a transaction journal. APFS (E) is not correct in this context because, although it is a modern copy-on-write file system with crash protection, it does not use a traditional journaling mechanism like NTFS, ext4, or HFS+.
During a forensic investigation, an analyst finds a file with a creation timestamp earlier than the volume's formatted timestamp. Which of the following is the most likely explanation?
Explanation: Timestamp manipulation is a known anti-forensic technique. File system metadata, including creation timestamps, can be altered using tools like `SetFile` (macOS) or `touch` (Linux) with the `-t` flag, or via direct hex editing of the MFT entry in NTFS. A creation timestamp earlier than the volume format timestamp is a strong indicator of deliberate tampering, as no legitimate file creation can occur before the volume itself exists.
In an ext3 file system, after deleting a file, the inode's link count drops to 0, but the data blocks remain. Which of the following is true regarding recovery?
Explanation: After a file is deleted in ext3, the inode's link count drops to 0 and the inode is marked as free, but the inode structure and data blocks remain intact until overwritten. Therefore, file carving (B) can recover the file by searching for known file signatures in the unallocated data blocks. Additionally, tools like extundelete or debugfs can recover the file by scanning the inode table for inodes with link count 0 and using their still-valid block pointers (D). The journal does not provide a rollback mechanism for file deletion (A is false), and ext3 does not zero the inode on deletion (C is false).
An investigator uses the Volatility framework on a memory dump from a Windows 10 system. Which command would list all processes, including those hidden by rootkits?
Explanation: `psxview` in the Volatility framework is specifically designed to detect hidden processes by cross-referencing process listings from multiple sources (e.g., PsActiveProcessHead linked list, EPROCESS pool scanning, and CSRSS handle table). This allows it to reveal processes that rootkits have hidden by unlinking them from the standard list, which `pslist` and `pstree` rely on.
+15 more Storage Forensics and File System Analysis questions available
Practice all Storage Forensics and File System Analysis questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Storage Forensics and File System Analysis. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Storage Forensics and File System Analysis questions on the CHFI frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Storage Forensics and File System Analysis is tested as part of the Computer Hacking Forensic Investigator CHFI blueprint. Practicing with targeted Storage Forensics and File System Analysis questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CHFI practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Storage Forensics and File System Analysis is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Storage Forensics and File System Analysis practice session with instant scoring and detailed explanations.
Start Storage Forensics and File System Analysis Practice →