CHFI Storage Forensics and File System Analysis Practice Question
An analyst finds evidence that an attacker used steganography to hide data within image files on the suspect's computer. Which of the following tools is MOST appropriate for detecting steganography in these images?
⚠ Common exam trap
EC-Council often tests the distinction between file recovery tools (like Foremost) and steganography detection tools, leading candidates to mistakenly choose Foremost because it is associated with 'hidden' data recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stegdetect
Stegdetect is specifically designed to detect steganographic content in images by analyzing statistical anomalies in pixel data, such as those introduced by LSB (Least Significant Bit) embedding. It can identify common steganography tools like JSteg, JPHide, and OutGuess, making it the most appropriate choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Foremost
Why it's wrong here
Foremost is a file carving tool that recovers deleted files by scanning raw disk images for file headers and footers, reassembling fragmented data based on known file signatures. It can extract images from unallocated space but does not inspect the content or encoding of those files for hidden messages, so it cannot determine whether steganography was used.
- ✗
Autopsy
Why it's wrong here
Autopsy is a comprehensive digital forensics platform with a graphical interface and modular ingest modules for analyzing disk images, browser history, and artifacts. Although some Autopsy modules may integrate third-party steganography detectors, the platform itself is not a dedicated steganography detection tool; Stegdetect is specifically engineered for that narrow purpose and is more directly applicable to the reported evidence.
- ✓
Stegdetect
Why this is correct
Stegdetect is a specialized static analysis tool that scans image files for signatures of common steganographic algorithms such as jsteg, outguess, and F5. It performs statistical tests and histogram analysis on JPEG coefficients to identify embedded payloads, making it the most direct and purpose-built choice for confirming steganographic content in a suspected image.
- ✗
Volatility
Why it's wrong here
Volatility is a memory forensics framework designed to analyze RAM dumps, extracting running processes, network connections, and injected code from volatile memory. While steganographic payloads might be present in memory as loaded data, Volatility does not scan image files for steganographic signatures; its purpose is memory artifact extraction, not image content analysis.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.