CHFI Storage Forensics and File System Analysis Practice Question
A security analyst receives an image of a hard drive with a GPT partition table. Which of the following is a key difference between GPT and MBR that the analyst should consider?
⚠ Common exam trap
Candidates often confuse the protective MBR with a regular MBR partition table, thinking GPT has no MBR at all, or they mistakenly believe GPT stores all partition data only in the first sector, when in fact the protective MBR is a distinct compatibility layer that does not contain the actual GPT partition entries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GPT uses a protective MBR to prevent legacy tools from misinterpreting the disk
GPT uses a protective MBR (Master Boot Record) at sector 0 of the disk to maintain backward compatibility with legacy BIOS-based tools that expect an MBR. This protective MBR contains a single partition entry of type 0xEE that covers the entire disk (or up to 2 TiB), preventing older utilities from misinterpreting the GPT disk as unformatted or overwriting GPT structures. This is a key architectural difference from MBR, which has no such protective mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GPT stores partition information only in the first sector of the disk
Why it's wrong here
The GPT structure is not confined to the first sector. Sector 0 holds a protective MBR, LBA 1 holds the primary GPT header, and LBAs 2–33 typically store the partition entry array; a backup GPT header and backup entries mirror this data at the end of the disk to enable recovery if the primary structures are corrupted.
- ✓
GPT uses a protective MBR to prevent legacy tools from misinterpreting the disk
Why this is correct
GPT deliberately places a legacy MBR at LBA 0 containing a single protective partition of type 0xEE that claims the whole disk. This makes traditional MBR-only utilities recognize the disk as already partitioned and belonging to an unknown OS, preventing them from misinterpreting the GPT layout and overwriting data while still allowing UEFI firmware to locate the real GPT header.
- ✗
GPT supports up to 4 primary partitions; MBR supports up to 128
Why it's wrong here
The limits are reversed between the two schemes. MBR supports at most four primary partition entries in its 64-byte partition table, with extended partitions needed for more logical volumes, whereas GPT supports up to 128 partitions in the default 16,384-byte entry array under Windows, and more if the array is enlarged. Thus, GPT does not have the four-partition ceiling.
- ✗
MBR uses a GUID partition table; GPT uses a simple table at sector 0
Why it's wrong here
This option inverts both the technology and the sector layout. MBR uses a simple 64-byte partition table in the first sector with four 16-byte entries, while GPT uses a GUID Partition Table with a header and entries at LBA 1 and beyond. There is no GUID table in MBR, and GPT does not rely on a simple table at sector 0 because that sector is reserved for the protective MBR.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.