Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

An investigator needs to parse and analyze a Microsoft Outlook personal folders file (.pst). Which tool is specifically designed for this purpose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Aid4Mail

Aid4Mail is a forensic email analysis tool that can parse Outlook PST files, among other formats, and extract metadata, attachments, and headers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Aid4Mail

    Why this is correct

    Aid4Mail is purpose-built for email forensics, with a native parser that navigates Outlook's proprietary PST B-Tree structure and heap-node architecture to extract individual items such as messages, contacts, and calendar entries. It handles both ANSI and Unicode PST formats, preserves metadata and deleted-item remnants, and can export evidence to MSG, EML, or PDF while maintaining hash integrity for court presentation. This makes it the correct choice over generic disk or network tools for analyzing an Outlook mailbox.

  • ✗

    FTK Imager

    Why it's wrong here

    FTK Imager is a forensic imaging and preview tool that captures sector-level disk images and mounts them for file browsing, but it does not include an email container parser. When pointed at a PST, it treats the file as an opaque blob, showing the raw binary or allowing extraction of the file itself, but it cannot enumerate the mailbox folders, recover individual messages, or decode the internal B-Tree nodes that hold Outlook items. Its role is acquisition and triage of evidence, not deep parsing of proprietary email databases.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer that decodes live captures and pcap files, focusing on packet-level communications over Ethernet, TCP/IP, HTTP, and similar protocols; it has no filesystem or email-container input module. A PST file does not traverse the network after it is stored locally, so Wireshark would have no method to read the file from disk, let alone reconstruct the hierarchical folder and message structure. Using Wireshark for PST analysis would be like using a spectrum analyzer to read a hard drive—completely mismatched to the evidence format.

  • ✗

    Sleuth Kit

    Why it's wrong here

    Sleuth Kit operates at the filesystem and disk-image level, parsing raw disk structures such as MFT entries and inodes, but it lacks any internal parser for the proprietary B-Tree and heap-node architecture of a .pst file. It is tempting because Sleuth Kit is a powerful open-source forensic suite for recovering deleted files and carving unallocated space from NTFS, FAT, or ext4 volumes—tasks where it would be the correct choice for a disk-imaging investigation, not for a single-format email container.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.