Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

During a forensic investigation of a Windows 10 system, you find that a suspect used the 'cipher /w:C:' command. What is the primary forensic implication of this action?

⚠ Common exam trap

Candidates often confuse the 'cipher' command's encryption functionality (using /e) with its free-space wiping capability (using /w), leading them to incorrectly select Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It wipes free space, hindering recovery of deleted files

The 'cipher /w:C:' command overwrites all free space on the C: drive with three passes of random data (0x00, 0xFF, and a random byte). This action permanently destroys the remnants of previously deleted files, making them unrecoverable by forensic tools. The primary forensic implication is that it severely hinders the recovery of deleted files, which is a common anti-forensic technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It encrypts all files on the C: drive

    Why it's wrong here

    The cipher /w command is exclusively a utility for overwriting unallocated disk space, not for encryption. While the cipher utility can encrypt or decrypt files and directories when used with /E or /D, the /w switch performs a different function entirely: it writes over freespace on the selected volume. Therefore, the claim that cipher /w encrypts all files on the C: drive is incorrect; it does not alter the encrypted state of any existing data.

  • ✓

    It wipes free space, hindering recovery of deleted files

    Why this is correct

    When you delete a file, its data blocks are merely marked as available, leaving the underlying bytes on the physical disk. The cipher /w command systematically overwrites these free-space regions with a sequence of patterns (e.g., 0x00, 0xFF, and random data) to ensure that remnants of deleted files are no longer recoverable through forensic tools. This process directly impedes recovery by destroying the residual data that would otherwise remain on the drive, which is why this is the correct description of the command's purpose.

  • ✗

    It enables file system journaling

    Why it's wrong here

    File system journaling is a native feature of filesystems such as NTFS, which uses a change journal or log to track metadata and file changes for crash recovery. The cipher /w command has no interaction with journaling mechanisms; it operates at the raw disk level, writing data to free space without altering filesystem metadata or enabling any logging functionality. Since journaling is an inherent filesystem property rather than something a command can activate, this option is factually incorrect.

  • ✗

    It removes alternate data streams from files

    Why it's wrong here

    Alternate Data Streams (ADS) are NTFS metadata structures that allow additional named data streams to be attached to a file, and they are not specifically addressed by the cipher /w command. The /w switch targets free disk space only, not the contents of active files or their associated streams. While overwriting may incidentally affect data blocks that contain streams if those blocks are in unallocated space, cipher /w does not proactively scan for or remove alternate data streams from existing files, making this explanation inaccurate.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.