CHFI Storage Forensics and File System Analysis Practice Question
An analyst is investigating a compromised Linux system. Which file system structure holds metadata about every file and directory, including permissions, ownership, timestamps, and pointers to data blocks?
⚠ Common exam trap
EC-Council often tests the misconception that the superblock holds per-file metadata, but the superblock only stores file system-wide configuration, not individual file attributes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inode
The inode is the fundamental data structure in Unix/Linux file systems (e.g., ext2/3/4) that stores metadata for each file and directory, including permissions, ownership, timestamps (access, modify, change), and pointers to data blocks. Unlike the superblock or block bitmap, the inode does not store the file name (which is in directory entries) but contains all other essential metadata required for file system operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Journal
Why it's wrong here
In ext4 and other journaling file systems, the journal is a circular log that records the intent to update metadata and sometimes data before those changes are committed, enabling crash recovery. It does not store static per-file attributes such as uid/gid, mode, timestamps, or block pointers; instead, it captures transactional redo/undo records for those structures. While journal remnants may contain fragments of deleted file data or names, the authoritative metadata source remains the inode, not the log.
- ✗
Block bitmap
Why it's wrong here
The block bitmap is a per-block-group bit array, where each bit represents whether a corresponding data block is free or allocated. It tracks block allocation state only, not file ownership, permissions, timestamps, or the linkage of blocks into a file. A forensic examiner can use the bitmap to identify unreferenced blocks that may hold deleted data, but it cannot reveal which inode owns a block or provide any file attribute information.
- ✗
Superblock
Why it's wrong here
The superblock is the filesystem's global header, storing parameters such as block size, total and free block counts, inode count, filesystem state, and feature flags. It is replicated at fixed offsets across the volume and provides the geometry needed to locate other structures like inode tables and bitmaps. However, it contains no per-file metadata; individual inodes and directory entries, not the superblock, hold file-specific information such as ownership and timestamps.
- ✓
Inode
Why this is correct
The inode is a per-file data structure containing all metadata for a file or directory, including mode/permissions, owner and group, size, access/modification/change timestamps, link count, and pointers to data blocks (direct, indirect, or extents). In ext4, the inode number, together with a generation counter, uniquely identifies a file, and directory entries map names to inode numbers. When a file is deleted, the inode may be cleared but often remains recoverable until the inode is reused, making it the central artifact for reconstructing file metadata and content.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.