Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

During a forensic examination of a Windows 10 system, you find a file with an ADS named `:hidden.txt` attached to `legal.docx`. Using FTK Imager, you extract the ADS and discover it contains a list of passwords. Which tool or technique could also be used to identify this hidden data?

⚠ Common exam trap

Candidates often assume ADS can only be detected via command-line tools like `dir /r` or `streams.exe`, but the EC-Council's CHFI exam tests understanding that the $MFT is the definitive source for all file metadata, including hidden streams, and that forensic tools like Autopsy leverage this for analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyzing the $MFT using Autopsy

The $MFT (Master File Table) in NTFS stores metadata for every file and directory, including entries for Alternate Data Streams (ADS). By analyzing the $MFT with a tool like Autopsy, you can directly view the ADS names and their associated data, such as the `:hidden.txt` stream attached to `legal.docx`. This is a reliable forensic method because the $MFT is a critical file system structure that records all streams, even if the file system explorer hides them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Analyzing the $MFT using Autopsy

    Why this is correct

    Autopsy's NTFS parser ingests the Master File Table, enumerating every file and its attributes, including the $DATA attribute's named streams. When a file has an alternate data stream, Autopsy displays it (e.g., file.txt:stream.txt) in the tree and the file properties, allowing the examiner to see both the stream's name and its content. This is correct because ADS entries are metadata stored in the MFT, not separate files, so they are only discoverable through filesystem metadata parsing.

  • ✗

    Running `strings` on the raw partition

    Why it's wrong here

    `strings` extracts sequences of printable ASCII or Unicode characters from a raw byte stream, but it has no filesystem awareness. When run on a raw partition, it will dump printable content from all files, MFT entries, and even unallocated space, mixing an ADS's payload with ordinary file content; it cannot associate any found string with a particular stream name or parent file. Because ADS data is stored inside a file's $DATA attribute, raw string extraction lacks the structural context needed to identify it as an ADS at all.

  • ✗

    Using `lsof` on a live system

    Why it's wrong here

    `lsof` enumerates files that are currently open by running processes, making it useful for live-response triage, not for full forensic enumeration. An alternate data stream that is not actively accessed by an application—or that resides on an offline system or image—will not appear in lsof's output. Moreover, `lsof` is not native to Windows 10; while ports exist, they still only reflect open file handles, so the majority of ADS entries remain invisible to this approach.

  • ✗

    Performing file carving with PhotoRec

    Why it's wrong here

    PhotoRec performs signature-based carving, scanning disk blocks for known file headers (magic numbers) and attempting to reconstruct (typically deleted) files. It completely ignores the NTFS filesystem structure, so it cannot read the MFT to discover named $DATA attributes. An ADS such as `innocent.txt:payload.exe` has no standalone file header or directory entry—it exists only as an attribute within another file's MFT record—so carving cannot isolate it, and even if the stream's contents are recovered, the association with the parent file is lost.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.