Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

An analyst is preparing to analyze a RAID 5 array of three disks. The analyst wants to reconstruct the logical volume for file system analysis. Which THREE steps are essential in this process?

⚠ Common exam trap

EC-Council often tests the misconception that you must run file system repair tools (like `chkdsk`) on individual disks before reconstruction, but this is incorrect because those tools require a logical volume and can corrupt the RAID metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a tool like `mdadm` (Linux) or RAID reconstructor (Windows) to assemble the array

The essential first step is to assemble the RAID 5 set from the member disks using a tool such as mdadm on Linux or a RAID reconstructor on Windows, because the logical volume must be presented to the OS before file system analysis can occur (A). Before assembly, the analyst must determine the disk order and stripe (chunk) size, since RAID 5 distributes data across all members in a specific sequence and wrong parameters yield an unreadable volume (C). The analyst must also identify the parity rotation method (e.g., left-symmetric, right-asymmetric), because parity placement determines how each stripe's data and parity blocks are arranged and must match the original configuration (D). Zeroing the first sector (B) is destructive and unnecessary, as it would erase metadata needed for reconstruction, and running chkdsk on individual member disks (E) is invalid because each disk holds only fragments of the file system, not a complete volume.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a tool like `mdadm` (Linux) or RAID reconstructor (Windows) to assemble the array

    Why this is correct

    RAID 5 forensic analysis requires rebuilding the logical volume from the member disk images; `mdadm` can assemble the array by reading on-disk superblocks, while tools like RAID Reconstructor automate the cross-drive stripe and parity calculation. Simply imaging each disk separately leaves the filesystem fragmented across all three drives, so the examiner must first combine the disks into a coherent logical device before mounting or parsing the filesystem for evidence.

  • ✗

    Zero out the first sector of each disk to remove remnants of previous arrays

    Why it's wrong here

    Zeroing the first sector of each member disk is catastrophic because that region may contain the RAID superblock (e.g., Linux md superblock version 0.9 stored at offset 0), partition metadata, or boot-sector structures critical to identifying the array layout. Even if the superblock resides elsewhere, overwriting the first sector destroys the partition table and filesystem boot sector after reconstruction, and constitutes intentional data destruction that could defeat forensic analysis and chain-of-custody arguments.

  • ✓

    Determine the disk order and stripe size

    Why this is correct

    The disk order and stripe size are foundational RAID 5 parameters: the order determines which physical disk supplies the first chunk of each stripe, and the chunk size defines where each segment begins and ends across the member drives. If either value is wrong, the reconstructed volume will be byte-shifted and the filesystem structures (like NTFS $MFT or ext4 superblock) will be unrecognizable, preventing any meaningful forensic recovery.

  • ✓

    Identify the parity rotation method (left-symmetric, etc.)

    Why this is correct

    Parity rotation method (left-symmetric, left-asymmetric, right-symmetric, or right-asymmetric) determines the exact position of the parity block and the logical ordering of data blocks within each stripe. XOR reconstruction depends on selecting the correct parity placement; choosing the wrong algorithm produces garbage on every stripe where parity is needed to rebuild a failed disk, silently corrupting the recovered data.

  • ✗

    Run `chkdsk` on each individual disk before reconstruction

    Why it's wrong here

    Running `chkdsk` against each raw physical member disk is invalid because those disks do not expose a mounted filesystem volume — the filesystem only exists after the RAID is logically assembled. `chkdsk` would misinterpret striped and parity blocks as disk metadata and may write 'repairs' to the individual disks, destroying the original evidence and making array reconstruction far more difficult; filesystem integrity checks belong on the reconstructed logical volume.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.