CHFI Storage Forensics and File System Analysis Practice Question
An examiner acquires a forensic image of an SSD from a suspect's laptop. The SSD was connected to a system with TRIM enabled. What challenge will the examiner most likely face when trying to recover deleted files?
⚠ Common exam trap
Watch out — candidates often confuse TRIM with wear leveling or encryption, assuming that wear leveling (Option A) is the main obstacle, when in fact TRIM's immediate physical erasure of deleted data is the far more critical and specific challenge for SSD forensics in the CHFI exam context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deleted files may have been physically erased by TRIM
When TRIM is enabled on an SSD, the operating system sends ATA DATA SET MANAGEMENT commands to the drive to immediately erase the physical blocks corresponding to deleted files. This means the deleted file data is permanently and irreversibly erased at the flash memory level, making recovery via traditional file carving or forensic tools impossible. Option D correctly identifies this as the primary challenge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wear leveling complicates data location
Why it's wrong here
Wear leveling does dynamically redistribute logical blocks across NAND cells, but it only relocates data that is still considered valid; the erased blocks are part of the SSD's normal FTL mapping. Deleted file sectors become stale, and wear leveling alone does not guarantee that a stale block is erased, since the controller may wait until the block is reused. Thus wear leveling adds complexity to locating data but is not the reason deleted files disappear; TRIM's explicit block erasure is.
- ✗
RAID striping interferes with imaging
Why it's wrong here
RAID striping is a valid concern when imaging a multi-disk array, as the examiner would need to reconstruct the logical volume from the striped components. However, this scenario states only that a single SSD is acquired; no RAID configuration has been mentioned or implied. Without evidence of striping across multiple physical disks, RAID is irrelevant to the imaging process.
- ✗
The SSD is encrypted and cannot be imaged
Why it's wrong here
Encryption is a plausible concern in any forensic case, yet nothing in the scenario indicates that the SSD is encrypted. Moreover, even full-disk encryption does not make imaging impossible—tools can still create a bit-for-bit copy, and decryption is a separate analysis challenge. Therefore encryption cannot be the reason deleted files are unrecoverable here, whereas TRIM's physical erasure directly addresses the data loss.
- ✓
Deleted files may have been physically erased by TRIM
Why this is correct
Upon file deletion, modern operating systems send TRIM commands to the SSD, which instructs the controller to mark the affected NAND blocks as invalid and subsequently erase them during garbage collection. Consequently, the original file data is physically removed from the flash memory, not merely marked as free space like on a hard drive. This makes deleted-file recovery and carving from unallocated SSD space far less reliable, so the artifacts may truly be gone.
Go deeper
Related to this question
Learn chapter
Data Acquisition and Duplication Techniques
Key term
Data Carving
Data carving is the process of recovering files and data fragments from a storage device without relying on the file system metadata.
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.