CHFI OS and Network Forensics Practice Question
A forensic investigator is examining a Linux system and suspects that files were deleted to cover tracks. The investigator runs 'debugfs -R "lsdel" /dev/sda1' on an ext4 file system. The output shows several deleted inodes but does not include file names. What is the MOST likely reason for the missing file names?
⚠ Common exam trap
The trap here is assuming that deleted inodes retain file names, when in fact names are stored separately in directory entries and are removed upon deletion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ext4 file system does not store file names in the inode; they are stored in directory entries, which are removed upon deletion.
In ext4, file names are stored in directory entries that map names to inode numbers. When a file is deleted, the directory entry is removed, but the inode may remain allocated or partially intact until reused. The debugfs lsdel command lists deleted inodes, but it cannot retrieve original file names because that information is not stored in the inode. Therefore, the missing names are expected behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file names were encrypted by the attacker, so they do not appear in plain text.
Why it's wrong here
If file names were encrypted, they would still appear as encrypted strings in directory entries, but lsdel does not report names at all because directory entries are removed. Encryption would not cause lsdel to omit names; it would only make them unreadable. The scenario does not indicate encryption was used, and the fundamental reason is the separation of names from inodes.
- ✗
The file system was mounted read-only, preventing debugfs from reading directory entries.
Why it's wrong here
Mounting read-only would not prevent debugfs from reading the file system; debugfs operates on the raw device and can read even if mounted. Moreover, a read-only mount would not cause lsdel to omit file names. The real issue is that deleted files lose their directory entries, so names are not available from the inode list. The mount status is irrelevant to the output of lsdel.
- ✗
The debugfs lsdel command only works on ext3 file systems and not on ext4.
Why it's wrong here
The debugfs lsdel command supports ext4 as well, although its usefulness depends on how quickly inodes are reused. The absence of file names is not due to file system version incompatibility. In fact, debugfs is part of e2fsprogs and works with ext2, ext3, and ext4. The scenario states the command produced output, confirming it ran on the ext4 file system.
- ✓
The ext4 file system does not store file names in the inode; they are stored in directory entries, which are removed upon deletion.
Why this is correct
In ext4 (and other Unix-like file systems), file names are not stored in the inode. Instead, directory entries map names to inode numbers. When a file is deleted, the directory entry is removed, but the inode may retain metadata until it is reused. Thus, debugfs lsdel can list deleted inodes but cannot recover original file names from the inode alone. This is why file names are missing from the output.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.