CHFI Storage Forensics and File System Analysis Practice Question
During a forensic investigation, an analyst needs to recover recently deleted files from a FAT32 partition. Which of the following techniques is MOST effective for recovering files whose directory entries have been marked as deleted but the clusters have not yet been overwritten?
⚠ Common exam trap
This exam often tests the misconception that file carving tools such as foremost or photorec are always the only or best recovery method. In CHFI, when file system metadata remains intact, the preferred method is metadata-based recovery using forensic tools such as Autopsy, FTK, or EnCase. Manual hex editing of directory entries and FAT chains is a risky, non-standard practice and should not be chosen as the most effective technique.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using 'dd' to create a raw image and then 'photorec' to recover based on file signatures
In FAT32, deleting a file normally marks the directory entry's first byte as 0xE5 while the data clusters may remain intact. The preferred recovery approach is to use forensic tools that parse the file system metadata (directory entries and FAT), such as Autopsy, FTK, EnCase, or a specialized FAT recovery utility. Manual editing of the directory entry and recalculation of the FAT chain is not a standard CHFI technique and can damage evidence. Among the listed options, creating a raw image with dd and using Photorec is the most forensically sound workflow; Photorec recovers file content by file signatures. It is not as ideal as metadata-based tools when directory entries are available, but it is better than manually modifying the file system structures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Running 'scalpel' to extract fragments and reassemble based on metadata
Why it's wrong here
Scalpel is a carving tool, not needed here because directory entry exists.
- ✗
Using the 'foremost' tool to perform file carving based on file headers and footers
Why it's wrong here
File carving is necessary when directory entries are lost, but here the directory entry is intact and deleted.
- ✓
Using 'dd' to create a raw image and then 'photorec' to recover based on file signatures
Why this is correct
PhotoRec is a carving tool, used when file system metadata is damaged or missing.
- ✗
Editing the directory entry's first byte from 0xE5 to the original character and recalculating the FAT chain
Why it's wrong here
This restores the deleted file's directory entry, making it visible again. The FAT chain is usually still valid.
Go deeper
Related to this question
Learn chapter
Database Forensics: Investigating Data Breaches
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
Autopsy Tool
An open-source digital forensics platform used to analyze hard drives, recover deleted files, and uncover evidence from computers and storage media.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.