Courseiva

Native NTFS Data Hiding Methods: ADS and Slack Space

Which TWO of the following are valid methods to hide data on an NTFS file system without using external tools?

Quick Answer

The answer is Alternate Data Streams (ADS) and slack space. These are the two valid methods to hide data on an NTFS file system without using external tools because both are native NTFS features that exploit the file system’s own structure. ADS allows data to be appended to a file as a hidden stream, invisible to standard directory listings, while slack space uses the unused bytes between the end of a file and the end of its allocated cluster. On the Computer Hacking Forensic Investigator CHFI exam, this question tests your understanding of file system forensics and anti-forensics, often appearing as a trap where candidates might mistakenly choose third-party tools or encryption. A common memory tip is to remember that both methods are “free” and “built-in”—no downloads needed, just the file system itself. Think of ADS as a secret pocket on a file and slack space as the empty padding in a box; both are invisible unless you specifically look for them.

⚠ Common exam trap

EC-CHFI often tests the misconception that NTFS journals or MFT attributes can be used for data hiding without external tools, but only slack space and Alternate Data Streams (ADS) are native, supported mechanisms that do not require third-party utilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Embedding data in file slack space

A is correct because file slack space is the unused bytes between the end of a file's logical data and the end of its allocated cluster. On NTFS, when a file does not fill its last cluster, the remaining bytes (RAM slack and drive slack) can be written to without affecting the file's visible content. This is a native hiding method that requires no external tools, as the data is simply written to the slack region using standard file I/O operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Embedding data in file slack space

    Why this is correct

    File slack is unused space at the end of a cluster that can be filled with data.

  • ✗

    Storing data in the NTFS file system journal ($LogFile)

    Why it's wrong here

    The journal is not designed for data hiding; it logs transactions.

  • ✗

    Using the $Volume attribute in the MFT

    Why it's wrong here

    $Volume is a system attribute, not for data hiding.

  • ✗

    Encrypting data with EFS

    Why it's wrong here

    EFS encrypts, but does not hide existence of data.

  • ✓

    Using Alternate Data Streams (ADS)

    Why this is correct

    ADS can hide data in streams attached to files.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are methods used to hide data within the NTFS file system?

medium
  • A.USN Journal
  • ✓ B.File slack space
  • C.Volume Shadow Copy
  • ✓ D.Alternate Data Streams (ADS)
  • E.Encrypting File System (EFS)

Why B: File slack space (B) is correct because NTFS allocates disk space in clusters (typically 4 KB), so a file smaller than its last cluster leaves unused bytes between the logical end-of-file and the end of the allocated cluster; this residual space can be written with hidden data without altering the file's visible content. Alternate Data Streams (ADS) (D) are correct because NTFS supports multiple named data streams per file via the $DATA attribute, allowing extra data to be attached to a file (e.g., 'file.txt:hidden.txt') that standard directory listings and many tools do not display. The USN Journal (A) is a change-logging metadata feature that records file system modifications, not a concealment method. Volume Shadow Copy (C) creates point-in-time snapshots for backup/recovery, and EFS (E) provides encryption for confidentiality, neither of which is a technique for hiding data inside NTFS structures.

Variation 2. Which TWO of the following are valid methods for hiding data on an NTFS volume without using third-party tools? (Select 2)

medium
  • A.Creating a symbolic link to a hidden file
  • B.Encrypting the file with EFS
  • ✓ C.Slack space (file slack or volume slack)
  • ✓ D.Alternate Data Streams (ADS)
  • E.Using the $Recycle.bin folder

Why C: Option C is correct because NTFS allocates disk space in clusters, and when a file's logical size is smaller than the allocated cluster(s), the unused bytes form file slack (and unused clusters at the end of the volume form volume slack); data written into that slack is not visible through normal file reads and requires no third-party tool—just native OS utilities. Option D is correct because NTFS natively supports Alternate Data Streams, allowing extra data to be attached to a file via syntax like 'type secret > file.txt:stream', and this stream is not shown by default in Explorer or a standard 'dir' listing, making it a built-in hiding method. Option A is not a hiding method—a symbolic link is simply a reparse point that redirects to a target, and the link itself is visible; it does not conceal data. Option B, EFS encryption, protects confidentiality but does not hide the file's existence, as the file and its metadata remain visible. Option E, the $Recycle.bin folder, is a normal system folder for deleted items and does not provide a native concealment mechanism beyond ordinary file attributes.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.