Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

An investigator is analyzing a RAID 5 array consisting of three disks. One disk fails and is replaced. After rebuilding, the file system appears corrupted. What is the MOST likely cause?

⚠ Common exam trap

A common misconception is that any disk of the same interface type (e.g., SATA) can replace a failed disk in a RAID array, ignoring the critical requirement for identical or larger capacity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The replacement disk is smaller than the original

In a RAID 5 array, all disks must have the same capacity for the array to function correctly. If a replacement disk is smaller than the original, the RAID controller will either refuse to rebuild or will rebuild using only the smaller disk's capacity, truncating data and causing file system corruption. This is a common cause of post-rebuild corruption because the parity and data stripes are misaligned or missing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Two disks failed simultaneously

    Why it's wrong here

    A simultaneous two-disk failure in RAID 5 is catastrophic, not a subtle corruption issue. RAID 5 provides fault tolerance for exactly one disk failure; if a second disk fails before the first is rebuilt, the array loses all data and typically goes offline or is reported as 'failed' by the controller. This would appear as a missing logical drive, not as corrupted data or a rebuild error, so it cannot explain the investigator's symptom.

  • ✓

    The replacement disk is smaller than the original

    Why this is correct

    RAID 5 requires all member disks to have identical usable capacity, and the controller maps data across disks based on that fixed geometry. If the replacement disk is physically or logically smaller than the original, the controller cannot reconstruct the missing disk's full block range, causing rebuild I/O errors that may corrupt the logical drive or abort the rebuild entirely. This is a classic cause of apparent data corruption after a disk replacement, because the array's own metadata and data layout become inconsistent with the replacement disk's reduced sector count.

  • ✗

    The file system is not supported by the RAID controller

    Why it's wrong here

    RAID controllers operate at the block abstraction layer and are completely file-system agnostic — they see arrays of logical blocks, not files or directories. The file system type (NTFS, ext4, HFS+, etc.) is handled entirely by the operating system after the block device is presented, so an 'unsupported' file system would only prevent the OS from mounting the volume, never interfere with the RAID rebuild or cause underlying disk corruption. Consequently, this option is irrelevant to the reported array corruption.

  • ✗

    The array was configured with an incorrect stripe size

    Why it's wrong here

    The stripe size (or stripe width) is a static parameter defined when the RAID array is created and stored in the controller's metadata; it determines how many bytes of consecutive data are written to each disk before switching to the next. An 'incorrect' stripe size does not arise during a routine rebuild — the controller uses the original stripe size recorded in its configuration, so there is no mechanism for it to corrupt data. Even if the stripe size were changed manually, the array would need to be recreated, a process that destroys data rather than merely corrupting it, so this cannot be the cause of a rebuild error.

Quick reference

RAID Level Comparison

RAID LevelMin DisksFault ToleranceReadWriteUsable Capacity
RAID 02NoneExcellentExcellent100%
RAID 121 diskGoodModerate50%
RAID 531 diskGoodModerate67–94%
RAID 642 disksGoodLower50–88%
RAID 1041 disk per mirrorExcellentGood50%

RAID is not a backup strategy — it protects against disk failure but not against accidental deletion, ransomware, or site-level events.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.