CHFI Storage Forensics and File System Analysis Practice Question
An investigator recovers a file from unallocated space on an NTFS drive using file carving. The file appears to contain alternate data streams (ADS). Which tool can be used to list all ADS associated with a file on a live Windows system?
⚠ Common exam trap
EC-Council often tests the distinction between native Windows commands and Unix commands, leading candidates to mistakenly choose `ls -la` because they associate it with listing files, but it cannot reveal NTFS ADS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dir /r
The `dir /r` command is the correct tool because it is a native Windows command that lists all alternate data streams (ADS) associated with files on an NTFS volume. When used with the `/r` switch, `dir` displays the main file stream along with any named ADS, such as `:Zone.Identifier:$DATA`, which are hidden from standard directory listings. This makes it the most direct and built-in method for an investigator to enumerate ADS on a live Windows system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
dir /r
Why this is correct
dir /r is the correct command because the /r switch tells the Windows command interpreter to enumerate all Alternate Data Streams (ADS) associated with each file and directory on an NTFS volume. The output shows each stream in the form filename:streamname:$DATA along with its byte size, allowing the investigator to spot hidden data that normal dir listings omit. This is the native built-in way to reveal ADS without third-party tools.
- ✗
ls -la
Why it's wrong here
ls -la is a Unix/Linux command and is not a native command in the Windows cmd.exe environment, so it would typically fail or require a compatibility layer. Even when run in a Linux forensic environment against a mounted NTFS image, ls -la lists file names, permissions, ownership, sizes, and timestamps, but it does not enumerate NTFS Alternate Data Streams. Thus it cannot expose hidden ADS data.
- ✗
attrib
Why it's wrong here
attrib is an external command in Windows that displays or changes file attributes such as read-only, hidden, system, and archive. It does not inspect or list any data streams associated with a file; it only shows attribute flags and paths. Because ADS are stored separately from those attributes, attrib provides no visibility into hidden streams and therefore cannot reveal alternate data hidden data.
- ✗
fsutil
Why it's wrong here
fsutil is an NTFS-focused utility used for low-level file system operations like querying volume information, repairing master file table entries, or managing the USN journal. Although fsutil can query certain file metadata, it has no built-in option to list Alternate Data Streams on a file; ADS enumeration is not part of its intended functionality. As a result, fsutil cannot be used to discover hidden data embedded in ADS.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.