CHFI · domain
OS and File System Forensics
This domain covers forensic examination of Windows and Linux file systems: NTFS metadata (MFT, $LogFile, $UsnJrnl), FAT/exFAT structures, ext2/3/4 inodes and journaling, deleted-file recovery, timestamps, and evidence acquisition. Questions are scenario-based, asking you to interpret artifacts, choose sound acquisition methods, and explain what file-system records reveal about attacker or user activity.
Focused practice
Practice OS and File System Forensics questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about OS and File System Forensics
Be able to explain what NTFS and ext artifacts (MFT, inodes, journals, $UsnJrnl) reveal about file creation, deletion, and tampering, and to select a write-blocked, hashed acquisition method. The single most important thing: preserve evidence integrity while correctly interpreting file-system metadata.
NTFS artifacts: $MFT records, $LogFile, $UsnJrnl, $Bitmap, alternate data streams, and resident vs non-resident attributes
Linux ext inode fields, orphan inode handling, journal recovery, and interpreting syslog entries about deleted or unlinked files
Write-blocked, hash-verified forensic imaging (dd, FTK Imager, EnCase) preserving original evidence integrity
Deleted-file and slack-space recovery, plus MAC(b) timestamp interpretation and time-zone normalization across systems
Watch out for
Common OS and File System Forensics exam traps
- ▸Assuming a deleted file is unrecoverable because the directory entry is gone; NTFS $MFT and ext inodes may still hold metadata and data runs.
- ▸Imaging a live drive without a hardware or software write blocker, or skipping hash verification, which breaks evidence integrity and admissibility.
- ▸Treating file MAC times as absolute truth; they can be altered by attackers, and time-zone or system-clock differences mislead timelines.
Question index
All OS and File System Forensics questions (7)
Click any question to see the full explanation, or start a practice session above.
You are a forensic investigator responding to a security incident at a medium-sized company. The incident involved an attacker gaining unauthorized access to a Windows Server 2019 system. The server was taken offline by the IT team immediately after detection. Your task is to acquire forensic evidence from the server's hard drive. The server has a single 500 GB NTFS partition. You have a forensic workstation with a write blocker, a SATA-to-USB adapter, and a forensic imaging tool that supports both dd and EWF (E01) formats. The server is still physically in the server room, and the IT team has powered it off. You need to create a forensic image that preserves the integrity of the evidence and allows for efficient analysis. Which of the following is the most appropriate course of action?
Medium2A forensic investigator is examining a Windows 10 workstation that was seized after a suspected data exfiltration. The user claims they only used legitimate cloud storage. The investigator wants to determine which USB mass storage devices were previously connected to the system by examining the Windows registry. Which registry location should the investigator examine to find the device instance IDs and associated volume serial numbers of previously connected USB storage devices?
Medium3A forensic investigator is analyzing a Linux system that was compromised. The investigator needs to examine the file system for evidence of unauthorized access. The system uses the ext4 file system. Which TWO of the following file system artifacts can provide evidence of file creation, modification, or access times? (Choose two.)
Medium4During a forensic investigation of a Windows 10 system, you need to analyze the file system to recover deleted files. Which TWO file system artifacts would be most useful for this purpose?
Medium5You are a forensic investigator responding to an incident on a Windows 10 workstation used by a finance manager. The user reports that a critical spreadsheet containing quarterly budget data was accidentally deleted from the Desktop yesterday at approximately 3:00 PM. The system has been used normally since then, and the user has not emptied the Recycle Bin. You have created a forensic image of the drive using FTK Imager. The Recycle Bin contains a file named 'Quarterly_Budget.xlsx', but it appears to be a shortcut (size 1 KB). The user insists the original file was several megabytes. You need to recover the original file. Which action should you take next?
Easy6During a forensic investigation, an analyst needs to preserve the integrity of evidence on a hard drive. Which of the following is the best practice for acquiring an image of the drive?
Easy7A forensic analyst is reviewing the syslog from a compromised Linux server. Based on the exhibit, what does the 'orphan inode deleted' message indicate?
HardOther domains
All CHFI exam domains
Frequently asked questions
- What does the OS and File System Forensics domain cover on the CHFI exam?
- Be able to explain what NTFS and ext artifacts (MFT, inodes, journals, $UsnJrnl) reveal about file creation, deletion, and tampering, and to select a write-blocked, hashed acquisition method. The single most important thing: preserve evidence integrity while correctly interpreting file-system metadata.
- How many questions are in this domain?
- This page lists all 7 OS and File System Forensics questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only OS and File System Forensics questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.