Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

A forensic investigator is analyzing an ext4 file system from a Linux server. The investigator needs to locate the superblock, which contains critical file system metadata such as block size, total inode count, and mount count. The primary superblock is damaged, so the investigator must find a backup superblock. Which of the following commands or methods is most appropriate to locate a backup superblock on the ext4 file system?

⚠ Common exam trap

Test-takers frequently confuse NTFS concepts like the `$MFT` with ext4 structures, or assuming that `fsck.ext4 -b` can automatically find backup superblocks when it requires a specific block number.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run `mke2fs -n /dev/sdX` to simulate file system creation and display the locations of backup superblocks without writing to the device.

In ext4, backup superblocks are located at fixed block offsets, typically at block group boundaries. The `mke2fs -n` command simulates file system creation and prints the locations of these backup superblocks without writing to the disk, making it a safe and effective method to identify them. Other commands like `dumpe2fs` require a valid superblock to run, and `fsck.ext4 -b` needs a known backup block number. The `$MFT` is an NTFS structure and irrelevant to ext4.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Examine the `$MFT` file to find the backup superblock, as ext4 stores superblock backups in the Master File Table.

    Why it's wrong here

    The `$MFT` is a key structure in NTFS, not ext4. Ext4 does not use a Master File Table; it uses inodes and block groups. The superblock and its backups are stored at specific block offsets within the file system, not in an MFT. This option incorrectly applies an NTFS concept to an ext4 scenario, making it invalid.

  • ✓

    Run `mke2fs -n /dev/sdX` to simulate file system creation and display the locations of backup superblocks without writing to the device.

    Why this is correct

    The `mke2fs -n` command performs a dry run of file system creation, displaying the superblock and backup superblock locations without modifying the device. This is a safe way to identify backup superblocks on an ext4 file system when the primary superblock is damaged. The output includes the block size, number of blocks, and the locations of backup superblocks, which can then be used with `e2fsck -b` to repair the file system.

  • ✗

    Use the `dumpe2fs` command with the `-o superblock` option to list all backup superblock locations.

    Why it's wrong here

    The `dumpe2fs` command is used to dump ext2/ext3/ext4 file system information, but it does not have an `-o superblock` option for listing backup superblocks. The `-o` option is used to specify superblock and block group descriptors for alternate superblocks, but it does not list them. To list backup superblock locations, you would typically use `dumpe2fs` on a valid file system and look for the backup superblock information, or use `mke2fs -n`.

  • ✗

    Use the `fsck.ext4 -b 32768 /dev/sdX` command to automatically scan for and use the first available backup superblock.

    Why it's wrong here

    The `fsck.ext4 -b` option allows you to specify a backup superblock to use instead of the primary one, but it does not automatically scan for or locate backup superblocks. You must know the block number of the backup superblock to use it. Running `fsck.ext4 -b 32768` assumes that 32768 is a valid backup superblock, which may not be correct for all file systems. It does not scan for available backups.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.