Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

In an ext4 file system, after a file is deleted, the inode's di_mode field is set to 0 and the block pointers are cleared. However, the file content may still be recoverable until what happens?

⚠ Common exam trap

Watch out — candidates often confuse metadata operations (like journal commits or superblock updates) with actual data destruction, assuming that file system housekeeping erases content, when in reality only block overwrites remove the raw data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The data blocks are overwritten by new files

When a file is deleted in ext4, the inode's di_mode is set to 0 and block pointers are cleared, but the actual data blocks on disk remain unchanged. The file content remains recoverable until those specific data blocks are overwritten by new file data, because only then is the original content physically destroyed. This is why data recovery tools can often restore deleted files if the blocks have not been reused.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The data blocks are overwritten by new files

    Why this is correct

    When a file is deleted in ext4, the inode is unlinked and its block pointers are cleared from the directory structure, but the physical blocks themselves are only marked as free in the block bitmap. They remain intact until a subsequent file allocation reuses those same blocks and overwrites them with new data. Once this happens, the original file content is irrecoverably lost unless remnants survive in unallocated slack space. Thus, overwriting by new files is the definitive event that destroys deleted file data.

  • ✗

    The file system is unmounted

    Why it's wrong here

    Unmounting the file system simply flushes all pending metadata and data buffers to disk and closes the device in a consistent state. It does not trigger any bulk zeroing or block reallocation; a deleted file's data blocks stay exactly as they were, still present but unreferenced. Even after many unmount cycles, the deleted content can be recovered with forensic tools as long as those blocks have not been overwritten. Consequently, unmounting is irrelevant to the physical preservation or destruction of file data.

  • ✗

    The superblock is updated

    Why it's wrong here

    The superblock is a metadata structure that tracks global file system parameters like total block count, free block count, and feature flags, and it is updated whenever block allocation changes. When a file is deleted, the free-block count in the superblock is incremented, but that is only a numeric accounting change. Updating the superblock does not modify the contents of the deleted file's data blocks, nor does it reassign them to any new file. Therefore, superblock updates have no direct impact on the recovery difficulty of deleted data.

  • ✗

    The journal is committed

    Why it's wrong here

    ext4's journal records transactions that happen before they are committed to the main file system, allowing the file system to recover after a crash. A journal commit marks a transaction as complete and ensures metadata (such as the inode's link count and free-block count) is consistent, but it never overwrites the file's actual data blocks. In fact, the journal itself may contain copies of metadata blocks, not the file content, and it is retired after commit. Hence, journal commit is a metadata durability operation, not an erasure of deleted file data.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.