10+ practice questions focused on OS and File System Forensics — one of the most tested topics on the Computer Hacking Forensic Investigator CHFI exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start OS and File System Forensics PracticeDuring a forensic investigation of a compromised Linux server, an investigator needs to recover deleted files from an ext4 filesystem. Which method should the investigator use to maximize recovery of file content, considering the filesystem may have been partially overwritten?
Explanation: Both foremost and scalpel are file carving tools that recover data by scanning raw disk blocks for known file signatures (headers and footers). The condition 'filesystem may have been partially overwritten' suggests metadata may be unusable, so carving is appropriate. The explanation only justifies foremost but fails to differentiate it from scalpel, which performs essentially the same function. Therefore, both A and C are correct.
Which TWO of the following are valid locations in a Windows system where forensic evidence of USB device connection can be found?
Explanation: The SYSTEM\CurrentControlSet\Enum\USBSTOR registry key is a primary location where Windows records every USB storage device that has been connected to the system. Each device is listed under this key with a unique instance ID, including the vendor ID, product ID, and serial number, providing persistent evidence of USB connections even after the device is removed.
Drag and drop the steps to perform a forensic analysis of a Windows registry using RegRipper into the correct order.
Explanation: Registry analysis requires acquiring hives, running RegRipper with profiles, and correlating results.
Match each forensic acquisition method to its description.
Explanation: Live acquisition captures volatile data from a running system, dead acquisition captures non-volatile data from a powered-off system, logical acquisition captures file structure only, and physical acquisition captures the entire device. Common confusions include swapping live and dead, or logical and physical.
A forensic analyst is examining a Windows 10 system and needs to determine the last boot time of the system. Which registry hive and key should the analyst query to find this information?
Explanation: The SYSTEM hive stores system-wide configuration data, and the key 'CurrentControlSet\Control\Windows\' contains the 'ShutdownTime' value, which records the last system shutdown time. Since the last boot time is effectively the time after the last shutdown, querying this value provides the necessary information. This is a standard forensic artifact for determining system uptime and boot events on Windows 10.
+5 more OS and File System Forensics questions available
Practice all OS and File System Forensics questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of OS and File System Forensics. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
OS and File System Forensics questions on the CHFI frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. OS and File System Forensics is tested as part of the Computer Hacking Forensic Investigator CHFI blueprint. Practicing with targeted OS and File System Forensics questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CHFI practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but OS and File System Forensics is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full OS and File System Forensics practice session with instant scoring and detailed explanations.
Start OS and File System Forensics Practice →