CHFI Storage Forensics and File System Analysis Practice Question
A security analyst examines a compromised Windows server and finds a file named 'readme.txt' that appears legitimate. However, using `dir /r`, they discover an alternate data stream named 'readme.txt:hidden.exe'. What is the most likely purpose of this alternate data stream?
⚠ Common exam trap
The CHFI exam often tests the misconception that ADS are used for legitimate system functions like backups or logs, but the key is that ADS are a hiding mechanism for malicious content, not a standard feature for those purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is a malicious executable hidden in the file
Alternate data streams (ADS) in NTFS allow a malicious executable to be hidden within a legitimate file without affecting its visible size or content. The `dir /r` command reveals the ADS 'readme.txt:hidden.exe', indicating that an executable is attached to the file, which is a common technique to evade detection and execute malware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is a backup copy of the file
Why it's wrong here
While NTFS Alternate Data Streams (ADS) can theoretically hold any type of content, they are not used by Windows or standard backup tools for creating backup copies. Backups are normally performed via copy commands, backup agents, or Volume Shadow Copy, resulting in separate files or VSS snapshots, not hidden streams. The presence of a suspicious executable stream, especially on a compromised server, is far more consistent with an attacker hiding malware than with a legitimate backup operation.
- ✗
It is a symbolic link to another file
Why it's wrong here
A symbolic link is a reparse-point file object that points to another file or directory, and it is represented in the file system as a distinct entry with the 'symbolic link' attribute. An ADS is instead an additional data stream attached to an existing file, which does not alter the file's primary file-system semantics. Therefore, an analyst encountering an executable in an ADS would not mistake it for a symlink, because symlinks do not embed secondary executable streams and would not be launched via an alternate stream path.
- ✓
It is a malicious executable hidden in the file
Why this is correct
This is the most plausible finding because NTFS Alternate Data Streams are a well-known technique for concealing malicious payloads on a compromised Windows host. An attacker can write an executable into a stream of a benign file (e.g., `type evil.exe > report.txt:evil.exe`) and execute it using tools like PowerShell or `wmic`, allowing it to evade basic directory scanning and security software that only checks the primary data stream. On a server that is known to be compromised, an unrecognized executable stream is a strong indicator of malware persistence or lateral movement.
- ✗
It is a log file generated by the operating system
Why it's wrong here
Operating system logs, such as event logs, are stored in structured files like .evtx under C:\Windows\System32\winevt\Logs, or as standard text files in Logs directories, not as NTFS Alternate Data Streams. While some applications do use ADS for metadata (e.g., Zone.Identifier for downloaded files), it would be highly unusual for the OS to generate a log stream inside an arbitrary file, and a stream containing executable code would not match any standard logging behavior.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.