CHFI Application, Email and Cloud Forensics Practice Question
An investigator needs to parse and analyze a Microsoft Outlook personal folders file (.pst). Which tool is specifically designed for this purpose?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Aid4Mail
Aid4Mail is a forensic email analysis tool that can parse Outlook PST files, among other formats, and extract metadata, attachments, and headers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Aid4Mail
Why this is correct
Aid4Mail is purpose-built for email forensics, with a native parser that navigates Outlook's proprietary PST B-Tree structure and heap-node architecture to extract individual items such as messages, contacts, and calendar entries. It handles both ANSI and Unicode PST formats, preserves metadata and deleted-item remnants, and can export evidence to MSG, EML, or PDF while maintaining hash integrity for court presentation. This makes it the correct choice over generic disk or network tools for analyzing an Outlook mailbox.
- ✗
FTK Imager
Why it's wrong here
FTK Imager is a forensic imaging and preview tool that captures sector-level disk images and mounts them for file browsing, but it does not include an email container parser. When pointed at a PST, it treats the file as an opaque blob, showing the raw binary or allowing extraction of the file itself, but it cannot enumerate the mailbox folders, recover individual messages, or decode the internal B-Tree nodes that hold Outlook items. Its role is acquisition and triage of evidence, not deep parsing of proprietary email databases.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that decodes live captures and pcap files, focusing on packet-level communications over Ethernet, TCP/IP, HTTP, and similar protocols; it has no filesystem or email-container input module. A PST file does not traverse the network after it is stored locally, so Wireshark would have no method to read the file from disk, let alone reconstruct the hierarchical folder and message structure. Using Wireshark for PST analysis would be like using a spectrum analyzer to read a hard drive—completely mismatched to the evidence format.
- ✗
Sleuth Kit
Why it's wrong here
Sleuth Kit operates at the filesystem and disk-image level, parsing raw disk structures such as MFT entries and inodes, but it lacks any internal parser for the proprietary B-Tree and heap-node architecture of a .pst file. It is tempting because Sleuth Kit is a powerful open-source forensic suite for recovering deleted files and carving unallocated space from NTFS, FAT, or ext4 volumes—tasks where it would be the correct choice for a disk-imaging investigation, not for a single-format email container.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.