CHFI OS and File System Forensics Practice Question
A forensic investigator is analyzing a Linux system that was compromised. The investigator needs to examine the file system for evidence of unauthorized access. The system uses the ext4 file system. Which TWO of the following file system artifacts can provide evidence of file creation, modification, or access times? (Choose two.)
⚠ Common exam trap
The trap here is assuming that extended attributes or dentry cache hold timestamp information, but they serve different purposes: xattrs store security labels, and dentry cache is volatile memory, not persistent storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
File system journal (ext4 journal)
Inode timestamps (atime, mtime, ctime) directly record when a file was accessed, modified, or its metadata changed, providing a timeline of activity. The ext4 journal logs metadata transactions and can be analyzed to reconstruct recent file operations, including creation and deletion. Together, these artifacts offer valuable evidence of unauthorized file activity on the compromised system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
File allocation table (FAT)
Why it's wrong here
The File Allocation Table is used by FAT file systems, not ext4. Ext4 uses inodes and extents for file allocation. Therefore, the FAT is irrelevant to this scenario and cannot provide evidence of file activity on an ext4 file system.
- ✓
File system journal (ext4 journal)
Why this is correct
The ext4 journal records metadata transactions and can be used to reconstruct recent file system changes. It may contain records of file creation, deletion, and modification, even if the inode timestamps are altered or lost. Analyzing the journal can reveal evidence of file operations that occurred before the system was powered off.
- ✓
Inode timestamps (atime, mtime, ctime)
Why this is correct
Inode timestamps include atime (last access), mtime (last modification), and ctime (last status change). These timestamps are updated when files are accessed, modified, or their metadata changes. They are crucial for establishing a timeline of file activity and can show when a file was created, modified, or accessed, providing evidence of unauthorized changes.
- ✗
Directory entry (dentry) cache
Why it's wrong here
The dentry cache is an in-memory structure that speeds up pathname resolution; it is not persistent on disk and is lost when the system is powered off. It does not contain file timestamps or evidence of file operations that can be recovered from a disk image. Thus, it is not useful for forensic analysis of a powered-off system.
- ✗
Extended attributes (xattrs)
Why it's wrong here
Extended attributes store additional metadata such as access control lists, SELinux labels, or user-defined attributes. While they can provide context about file permissions and security contexts, they do not record timestamps for file creation, modification, or access. Therefore, they are not a primary source for timeline evidence.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.