CHFI Storage Forensics and File System Analysis Practice Question
An analyst is examining an NTFS volume and finds that a file's $MFT record indicates it is resident. What does this imply about the file's data?
⚠ Common exam trap
It's easy for candidates to confuse 'resident' with 'compressed' or 'sparse,' or assume resident files always use alternate data streams, when in fact residency simply means the data fits inside the MFT record.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file's data is stored within the $MFT record itself, suitable for small files
When a file's $MFT record indicates it is resident, the file's data is stored entirely within the $MFT record itself. This occurs for small files (typically under 512–1024 bytes) to optimize storage and access speed, as the data does not need to be placed in separate clusters on the NTFS volume.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file is compressed and stored across multiple clusters
Why it's wrong here
The NTFS compression attribute (the compressed bit in the file attribute flags) stores data using sparse clusters and multiple data runs across the volume, not within the $MFT record. A file with the COMPRESSED attribute still has its content in ordinary clusters, so this description does not match the finding that the file's data is entirely inside the MFT record. Compression is unrelated to resident file storage, making this option incorrect for the observed indicator.
- ✗
The file uses alternate data streams to hide data
Why it's wrong here
Alternate data streams (ADS) are additional named $DATA attributes attached to a file, allowing hidden content in separate streams. Even if a file contains an ADS, the main file data is not necessarily stored inside the $MFT record; the ADS itself could be resident or non-resident. The finding that the file's data is stored within the MFT record refers to the primary unnamed $DATA attribute, not to the use of hidden streams, so this option does not explain the observation.
- ✓
The file's data is stored within the $MFT record itself, suitable for small files
Why this is correct
In NTFS, a small file's entire content can be stored directly inside the $MFT record within a resident $DATA attribute, making it immediately accessible without reading additional clusters. This happens when the file's data is small enough to fit in the available space of the file's MFT record, often up to about 700 bytes depending on record size and attribute overhead. Thus, the file is correctly identified as having its data stored within the MFT record itself, which is a standard NTFS optimization.
- ✗
The file is a directory junction point
Why it's wrong here
A directory junction point is a reparse point that maps a directory name to a separate directory path, effectively acting as a symbolic link for folders. It does not involve storing file data inside the MFT record; instead, the reparse point attribute contains a target path. Therefore, this option mischaracterizes the NTFS feature that explains why the file's data is resident in the MFT record, making it an incorrect explanation for the observed file layout.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.