CHFI Storage Forensics and File System Analysis Practice Question
A forensic investigator is analyzing a Linux ext4 file system. They suspect a file was deleted but its inode may still be intact. Which tool can be used to recover the file by referencing the inode?
⚠ Common exam trap
The CHFI exam often tests the distinction between file carving tools (scalpel, foremost) and file system forensic tools (debugfs), expecting candidates to know that carving ignores metadata while debugfs leverages the inode structure for recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
debugfs
debugfs is an interactive file system debugger for ext2/ext3/ext4 that allows direct manipulation of inode structures. When a file is deleted but its inode remains intact, debugfs can recover the file by using the `lsdel` command to list deleted inodes and the `dump` command to extract the file contents by referencing the inode number.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
dd
Why it's wrong here
dd is a low-level disk imaging tool that performs a raw, bit-for-bit copy of an entire block device or partition. It does not interpret ext4 metadata such as the inode table, superblock, or directory entries, so it cannot locate or recover a specific file based on its inode number. While dd is essential for creating forensic images for offline analysis, it is not itself a file-recovery mechanism.
- ✗
scalpel
Why it's wrong here
scalpel is a file carver that recovers data by scanning raw disk blocks for known file header and footer byte signatures, completely bypassing the filesystem's inode structure. It has no knowledge of ext4 inodes, directory entries, or allocation bitmaps, so it cannot target a file by its inode. Carving may recover files only if their data blocks remain contiguous and intact, making it unreliable for inode-based recovery.
- ✗
foremost
Why it's wrong here
foremost also performs raw data carving using header/footer signatures and content-based recognition, descending from the original TCT carve tool. Like scalpel, it operates independently of ext4 metadata and has no facility to resolve inode numbers or traverse the inode tree. It is a legitimate tool for recovering files by type, but it is fundamentally unsuited for recovering a file specifically identified by its inode on an ext4 filesystem.
- ✓
debugfs
Why this is correct
debugfs is a filesystem debugger built specifically for ext2/ext3/ext4 that provides direct access to the on-disk inode structures. Commands such as `lsdel` list unlinked inodes and `cat <inode>` display file content by inode number, allowing targeted recovery of deleted files when the inode is still valid. Unlike carving tools, debugfs leverages the filesystem metadata itself, making it the correct choice for inode-based recovery.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.