Courseiva

CCNA Chfi Storage Filesystem Questions

75 of 139 questions · Page 1/2 · Chfi Storage Filesystem topic · Answers revealed

1
Multi-Selectmedium

A forensic analyst is investigating a compromised Linux server running an ext4 file system. The analyst suspects the attacker deleted critical log files (e.g., /var/log/auth.log) and wants to recover them. Which TWO techniques would be MOST effective for recovering the deleted files?

Select 2 answers
A.Running `extundelete` on the partition
B.Checking the `.Trash-1000` folder
C.Using `foremost` to perform file carving based on headers and footers
D.Restoring from the `lost+found` directory
E.Executing `dd if=/dev/sda1 of=image.dd` and analyzing with `strings`
AnswersA, C

Running `extundelete` on the partition is the correct approach because extundelete parses the ext3/ext4 journal to locate inodes and data blocks that were marked free after deletion, enabling reconstruction of the original file content even without filesystem metadata. Since system logs are typically removed with `rm`, which bypasses any trash mechanism, the journal often retains enough information to recover them—provided the partition is unmounted or mounted read-only to prevent subsequent writes from overwriting the freed blocks. This makes extundelete the most direct and appropriate forensic recovery method for deleted log files on an ext3/ext4 Linux server.

Why this answer

Option A is correct because `extundelete` is a specialized utility designed for ext3/ext4 file systems that reads the journal and inode tables to locate and restore recently deleted files, making it ideal for recovering deleted logs like /var/log/auth.log on an ext4 partition. Option C is correct because `foremost` performs file carving by scanning raw disk data for known file headers and footers, which can recover deleted files even when file system metadata (inodes) has been overwritten or is unavailable. Option B is incorrect because `.Trash-1000` is a per-user trash directory used by desktop environments, not a system-wide recovery location, and root-owned logs deleted by an attacker would not be moved there.

Option D is incorrect because `lost+found` is used by fsck to reconnect orphaned inodes (files with intact metadata but no directory entry), not to recover files whose inodes were freed upon deletion. Option E is incorrect because `dd` merely creates a bit-for-bit image and `strings` only extracts printable character sequences; neither reconstructs deleted files or their metadata, so this approach is not an effective recovery technique.

Exam trap

The EC-Council CHFI exam often tests the distinction between file system-specific recovery tools (like `extundelete`) and generic file carving tools (like `foremost`), and candidates mistakenly choose `lost+found` thinking it stores all deleted files, when it only holds files recovered from file system corruption.

2
MCQmedium

During a forensic examination of a Windows system, an analyst runs the Volatility plugin `netscan` on a memory dump. What information does this plugin primarily provide?

A.Network connections and listening sockets with associated processes
B.Open files and handles for each process
C.List of all running processes and their parent processes
D.The contents of the Windows firewall rules
AnswerA

This is correct because Volatility's netscan plugin specifically scans physical memory for Windows network structures, including TCP endpoints, TCP listeners, UDP endpoints, and UDP listeners. It pairs each socket with its owning process ID (PID) by traversing the _TCP_ENDPOINT, _TCP_LISTENER, and _UDP_ENDPOINT kernel structures. Thus it directly reveals active network connections and listening sockets along with the processes bound to them, which is the intended forensic artifact for network-related memory analysis.

Why this answer

The Volatility plugin `netscan` is specifically designed to extract network connection information from Windows memory dumps, including active TCP and UDP connections, listening sockets, and the associated processes that own them. It works by scanning kernel data structures such as `_TCPT_OBJECT` and `_UDP_OBJECT` to provide a snapshot of network activity at the time of capture, which is critical for identifying malicious connections or unauthorized services.

Exam trap

The EC-CHFI exam often tests the distinction between memory forensics plugins, and the trap here is that candidates confuse `netscan` with `pslist` or `handles`, assuming it provides process lists or file handles instead of network socket data.

How to eliminate wrong answers

Option B is wrong because open files and handles for each process are enumerated by the `handles` or `filescan` plugins, not `netscan`. Option C is wrong because listing all running processes and their parent processes is the function of the `pstree` or `pslist` plugins, which traverse the EPROCESS block list. Option D is wrong because Windows firewall rules are stored in the registry (e.g., `SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy`) and are not directly parsed by `netscan`, which focuses on network socket objects rather than policy configurations.

3
MCQeasy

A security analyst is investigating a compromised Windows server and wants to capture the contents of RAM for analysis. Which of the following tools is specifically designed for this purpose?

A.Foremost
B.WinPmem
C.Volatility
D.FTK Imager
AnswerB

WinPmem is a kernel-mode memory acquisition driver that provides a raw, bit-for-bit capture of physical memory on Windows systems, including the PFN database and kernel structures. It is specifically designed for forensic acquisition, with options for page-table manipulation to bypass some anti-forensic techniques and produce a memory image compatible with Volatility and other analyzers. Its low-level access to RAM makes it the standard choice on a live compromised server.

Why this answer

WinPmem is a dedicated memory acquisition tool designed to capture the contents of RAM from a live Windows system. It creates a raw memory dump file that can be analyzed with tools like Volatility, making it the correct choice for this forensic task.

Exam trap

The trap here is that candidates confuse FTK Imager's ability to capture a physical memory dump (via its 'Capture Memory' option) with it being the primary tool for this task, but WinPmem is the tool specifically designed and optimized for live RAM acquisition in forensic contexts.

How to eliminate wrong answers

Option A is wrong because Foremost is a file carving tool used to recover deleted files from disk images, not a memory acquisition tool. Option C is wrong because Volatility is a memory analysis framework used to examine RAM dumps, not to capture them. Option D is wrong because FTK Imager is primarily a disk imaging and forensic acquisition tool; while it can capture a pagefile or a physical memory dump on some systems, it is not specifically designed for live RAM capture and lacks the robust memory acquisition capabilities of WinPmem.

4
Multi-Selectmedium

Which THREE of the following are techniques used to hide data on a hard drive?

Select 3 answers
A.File carving
B.Host Protected Area (HPA)
C.Slack space
D.Alternate Data Streams
E.Hashing
AnswersB, C, D

Host Protected Area (HPA) is a reserved region on ATA/ATAPI hard drives that is defined by the SET MAX ADDRESS command, making it invisible to the operating system and standard disk utilities. Data stored in HPA lies beyond the reported maximum address, so it escapes normal filesystem enumeration and can only be accessed using special ATA commands such as IDENTIFY DEVICE or READ NATIVE MAX ADDRESS. Forensic examiners must consciously probe for HPA during imaging, as it is a common hiding location for covert data.

Why this answer

Host Protected Area (HPA) is correct because it is a hidden region of the disk, outside the normal addressable sectors reported to the OS, that can be used to conceal data from standard file system tools. Slack space is correct because the unused bytes between the logical end of a file and the end of its allocated cluster can store hidden data without changing the file's apparent size. Alternate Data Streams (ADS) is correct because NTFS allows multiple data streams to be attached to a single file, and these streams are not shown by ordinary directory listings, making them a common hiding technique.

File carving is not a hiding technique but a forensic recovery method for reconstructing files from raw disk data, and hashing is an integrity-verification technique that produces a fixed-length digest and does not conceal data.

Exam trap

The CHFI exam often tests the distinction between data hiding techniques (like HPA, slack space, and ADS) and data recovery or integrity techniques (like file carving and hashing), so candidates mistakenly select file carving or hashing because they associate them with forensic analysis rather than recognizing they do not hide data.

5
Multi-Selecteasy

Which two of the following are tools used for memory forensics acquisition? (Choose TWO.)

Select 2 answers
A.Autopsy
B.FTK Imager
C.WinPmem
D.Volatility
E.LiME
AnswersC, E

WinPmem is a dedicated memory acquisition tool for Windows that loads a kernel-mode driver to map and copy physical memory (RAM) into a raw image or an AFF4 container. Developed by the Rekall project and now maintained as part of the pmem suite, it is specifically engineered to produce a faithful snapshot of volatile memory for later analysis with Volatility or Rekall. Therefore, it is correct as a memory forensic acquisition utility.

Why this answer

WinPmem (C) is a memory acquisition tool that captures physical memory from live Windows systems into a raw image file, making it a correct choice for memory forensics acquisition. LiME (E) is a Loadable Kernel Module for Linux that acquires volatile memory to a file or over the network, and it is specifically designed for memory acquisition, so it is also correct. Autopsy (A) is a graphical digital forensics platform used primarily for disk image analysis and file system examination, not memory acquisition.

FTK Imager (B) is used for creating forensic disk images and mounting images, not for capturing RAM. Volatility (D) is a memory analysis framework that parses memory images after acquisition, so it is not an acquisition tool.

Exam trap

EC-Council often tests the distinction between memory acquisition tools (which capture RAM) and memory analysis tools (which examine captured dumps), so candidates may mistakenly choose Volatility (a popular analysis tool) as an acquisition tool.

6
MCQeasy

During a forensic analysis of a Windows 10 system, an investigator needs to locate the Master File Table ($MFT) to analyze file metadata. Which file system structure contains the $MFT?

A.ext4 superblock
B.FAT32's File Allocation Table
C.HFS+ catalog file
D.NTFS volume's Master File Table
AnswerD

The $MFT is the Master File Table, the core structure of the NTFS filesystem, and it holds 1024-byte file records for every file and directory, including system metadata files. Each record contains attributes such as $STANDARD_INFORMATION (timestamps, flags), $FILE_NAME, and $DATA, which investigators parse to enumerate files, examine MAC times, and uncover deleted entries. Since Windows 10 defaults to NTFS, this is the structure an investigator should analyze to retrieve file metadata.

Why this answer

The $MFT is a core component of the NTFS file system, storing metadata for every file and directory on the volume. It is located in the NTFS volume's designated Master File Table area, not in any other file system structure. Option D correctly identifies this NTFS-specific structure.

Exam trap

The trap here is that candidates may confuse the $MFT with other file system structures like the FAT (which tracks cluster chains) or assume it is a generic concept across all file systems, but EC-Council tests that the $MFT is exclusive to NTFS and is the primary source for file metadata in Windows forensics.

How to eliminate wrong answers

Option A is wrong because the ext4 superblock is a metadata structure for the Linux ext4 file system, not for Windows NTFS. Option B is wrong because FAT32's File Allocation Table tracks cluster allocation for files, not file metadata like timestamps or security descriptors. Option C is wrong because the HFS+ catalog file is part of Apple's HFS+ file system, used on macOS, and does not exist on Windows NTFS volumes.

7
MCQmedium

An analyst notices that a file on an NTFS volume occupies 4096 bytes on disk but its actual data is only 100 bytes. The extra space contains remnants of a previously deleted file. What is this extra space called?

A.Volume slack
B.Free space
C.RAM slack
D.File slack
AnswerD

File slack is the unused area within the last allocated cluster of a file, spanning from the bytes beyond the logical end of the file to the physical end of that cluster, and it is composed of both RAM slack and the remaining sector space. On NTFS, these bytes are not zeroed when a file is written, so they may contain residual data from previously deleted files or older versions of the current file, making them a valuable forensic source. This exactly matches the analyst's observation of a file occupying 40 clusters where some space is unused, because that space remains attributed to the file's allocated cluster rather than to free or volume slack.

Why this answer

File slack is the unused space between the end of the actual file data and the end of the last allocated cluster for that file. On an NTFS volume with a 4096-byte cluster size, a 100-byte file leaves 3996 bytes of slack space, which may contain remnants of previously deleted files. This is why option D is correct.

Exam trap

The trap here is that candidates confuse file slack with volume slack or free space, not realizing that file slack is specifically the unused portion within a file's allocated cluster(s) that can still hold residual data from prior file writes.

How to eliminate wrong answers

Option A is wrong because volume slack refers to the unused space at the end of a volume (partition) after the last cluster, not within a file's allocated clusters. Option B is wrong because free space is unallocated disk space not assigned to any file, whereas the extra space described is allocated to the file but unused. Option C is wrong because RAM slack is the space between the end of the file data and the end of the sector (typically 512 bytes), not the full cluster slack; RAM slack is a subset of file slack that exists only in the last sector of a file.

8
Multi-Selecthard

An analyst is conducting memory forensics on a Windows system using Volatility. Which THREE commands can provide information about network connections?

Select 3 answers
A.netscan
B.pstree
C.connscan
D.sockets
E.pslist
AnswersA, C, D

netscan is correct because it performs pool tag scanning to recover TCP and UDP endpoint objects from non-paged kernel memory, reliably identifying both listening and established connections on modern Windows versions. This plugin is specifically designed for network artifact extraction in memory forensics and provides complete connection tuples including local/remote IP and port, satisfying the analyst's need.

Why this answer

Option A, netscan, is correct because it scans for network artifacts such as TCP endpoints, listening sockets, and UDP connections across all memory pools, making it the modern Volatility plugin for network connection discovery. Option C, connscan, is correct because it scans physical memory for TCP connection objects (pool tag TcpE), revealing local and remote IP addresses and ports for established connections. Option D, sockets, is correct because it enumerates socket objects in memory, showing socket handles, protocols, and associated connection details.

Option B, pstree, is not correct because it displays parent-child process relationships, not network connections. Option E, pslist, is not correct because it lists active processes from the process list, which contains no network connection information.

Exam trap

The CHFI exam often tests the distinction between commands that list network connections (netscan, connscan, sockets) versus those that list processes (pslist, pstree), trapping candidates who confuse process enumeration with network artifact retrieval.

9
MCQhard

An analyst is examining a RAID 5 array of three disks. One disk has failed and been replaced; the array is rebuilding. Which of the following is the most significant forensic challenge regarding data acquisition from this array?

A.The failed disk cannot be imaged because it is physically damaged
B.The rebuild process may overwrite unallocated space or remnants of deleted files
C.RAID 5 arrays cannot be imaged using traditional tools like dd
D.The array must be imaged while degraded to preserve evidence
AnswerB

In RAID 5, when a disk is missing, the controller regenerates the lost data on the fly from parity on the remaining disks and writes the complete reconstructed dataset to a new disk. This rebuild operation writes across every block of the replacement disk and often touches unallocated space and slack on the other members as the array re-stripes or normalizes, potentially overwriting remnants of deleted files that could be critical evidence. Even if a physical copy of the failed disk is impossible, the evidence on the surviving disks is vulnerable to destruction by the rebuild write process. Therefore, the correct forensic action is to image all member disks first.

Why this answer

During a RAID 5 rebuild, the array controller reads parity and data from the remaining healthy disks to reconstruct the missing data onto the replacement disk. This process writes to the entire replacement disk, including areas that previously held unallocated space or remnants of deleted files, potentially overwriting critical forensic evidence. The rebuild is a low-level write operation that does not respect file system boundaries, making it a significant challenge for data acquisition.

Exam trap

EC-Council often tests the misconception that a failed disk is always unrecoverable (Option A) or that RAID arrays cannot be imaged with standard tools (Option C), while the real forensic challenge is the destructive nature of the rebuild process itself.

How to eliminate wrong answers

Option A is wrong because a failed disk can often be imaged using specialized hardware or techniques (e.g., PC-3000, chip-off recovery) even if physically damaged, and the question does not specify that the disk is physically damaged beyond recovery. Option C is wrong because RAID 5 arrays can be imaged using traditional tools like dd if the array is presented as a logical volume by the controller or by using software RAID (e.g., mdadm) to assemble the array; dd works on block devices regardless of RAID level. Option D is wrong because imaging an array while degraded (with a missing disk) is possible and may be necessary to avoid rebuild overwrites, but the question asks for the most significant forensic challenge, which is the active rebuild process overwriting data, not the degraded state itself.

10
MCQmedium

A forensic investigator is analyzing an ext4 file system from a Linux server. The investigator needs to locate the superblock, which contains critical file system metadata such as block size, total inode count, and mount count. The primary superblock is damaged, so the investigator must find a backup superblock. Which of the following commands or methods is most appropriate to locate a backup superblock on the ext4 file system?

A.Examine the `$MFT` file to find the backup superblock, as ext4 stores superblock backups in the Master File Table.
B.Run `mke2fs -n /dev/sdX` to simulate file system creation and display the locations of backup superblocks without writing to the device.
C.Use the `dumpe2fs` command with the `-o superblock` option to list all backup superblock locations.
D.Use the `fsck.ext4 -b 32768 /dev/sdX` command to automatically scan for and use the first available backup superblock.
AnswerB

The `mke2fs -n` command performs a dry run of file system creation, displaying the superblock and backup superblock locations without modifying the device. This is a safe way to identify backup superblocks on an ext4 file system when the primary superblock is damaged. The output includes the block size, number of blocks, and the locations of backup superblocks, which can then be used with `e2fsck -b` to repair the file system.

Why this answer

In ext4, backup superblocks are located at fixed block offsets, typically at block group boundaries. The `mke2fs -n` command simulates file system creation and prints the locations of these backup superblocks without writing to the disk, making it a safe and effective method to identify them. Other commands like `dumpe2fs` require a valid superblock to run, and `fsck.ext4 -b` needs a known backup block number.

The `$MFT` is an NTFS structure and irrelevant to ext4.

Exam trap

The trap here is confusing NTFS concepts like the `$MFT` with ext4 structures, or assuming that `fsck.ext4 -b` can automatically find backup superblocks when it requires a specific block number.

11
MCQhard

An analyst discovers a hidden partition on a hard drive that does not appear in the standard MBR partition table. The drive uses GPT partitioning. Which area of the disk should be examined to find evidence of a hidden partition?

A.The Master Boot Record (MBR) in sector 0
B.The GPT header and partition entry array located after the protective MBR
C.The Volume Boot Record (VBR) of the C: drive
D.The Host Protected Area (HPA) at the end of the disk
AnswerB

The GPT header and partition entry array located after the protective MBR are exactly where partition definitions live on a GUID Partition Table disk. The primary GPT header is at Logical Block Address 1 (right after the protective MBR in sector 0), and the partition entry array follows it; the header contains the partition table checksum and pointers to the entries, while the entries themselves (with unique GUIDs, start/end LBAs, and attributes) define each partition. A hidden partition may be deliberately omitted from the active partition table, but a forensic analyst scanning the entire disk for GPT-like structures—such as the header signature 'EFI PART' and backup headers at the end—can locate an alternate or stale partition entry array that reveals the hidden partition's existence and location.

Why this answer

In GPT partitioning, the protective MBR in sector 0 only contains a single partition entry of type 0xEE to prevent legacy tools from misinterpreting the disk. The actual partition information, including any hidden partitions, is stored in the GPT header (typically in sector 1) and the partition entry array that follows. Therefore, examining the GPT header and partition entry array is necessary to detect partitions not visible in the MBR.

Exam trap

EC-CHFI often tests the misconception that the MBR is the primary source of partition information on GPT disks, leading candidates to incorrectly choose Option A, when in fact the protective MBR is only a compatibility placeholder and the real partition data resides in the GPT structures.

How to eliminate wrong answers

Option A is wrong because the MBR in sector 0 on a GPT disk is a protective MBR that does not list actual partitions; it only contains a single entry of type 0xEE covering the entire disk, so hidden partitions cannot be found there. Option C is wrong because the Volume Boot Record (VBR) of the C: drive is a boot sector specific to a volume's file system (e.g., NTFS) and does not contain the disk's partition table; it is irrelevant for discovering hidden partitions. Option D is wrong because the Host Protected Area (HPA) is a reserved area at the end of the disk used by manufacturers for diagnostic tools, not a location where hidden GPT partitions are stored; GPT hidden partitions are defined within the GPT partition entry array.

12
MCQeasy

Which forensic tool is specifically designed to recover lost partitions or file system structures and can also be used for data carving?

A.Sleuth Kit
B.EnCase
C.TestDisk
D.Volatility
AnswerC

TestDisk rebuilds damaged partition tables and lost file system structures, and its bundled PhotoRec component performs file carving from unallocated space. This satisfies the stem's dual requirement, whereas tools such as Autopsy or EnCase analyse acquired images rather than repairing partition structures.

Why this answer

TestDisk is specifically designed to recover lost partitions and repair file system structures, making it the correct choice for this scenario. It also includes data carving capabilities through its companion tool PhotoRec, allowing it to recover files from unallocated space or damaged volumes.

Exam trap

The EC-CHFI exam often tests the distinction between tools designed for storage forensics (like TestDisk) versus memory forensics (like Volatility) or general forensic suites (like EnCase), leading candidates to choose a tool that is more well-known but not specialized for partition recovery.

How to eliminate wrong answers

Option A is wrong because Sleuth Kit is a collection of command-line tools for forensic analysis of disk images, but it does not have built-in partition recovery or data carving features; it relies on external tools like PhotoRec for carving. Option B is wrong because EnCase is a commercial forensic suite that can perform data carving and partition analysis, but it is not specifically designed for recovering lost partitions or file system structures; its primary focus is evidence acquisition and analysis. Option D is wrong because Volatility is a memory forensics framework used for analyzing RAM dumps, not for storage forensics tasks like partition recovery or data carving.

13
MCQhard

A forensic investigator is analyzing a RAID 0 array consisting of two disks. She uses FTK Imager to acquire the logical drive. However, the data appears interleaved. What additional step is necessary to properly assemble the image?

A.Use EnCase to acquire each disk separately and mount as a RAID volume
B.Simply reorder the disk images alphabetically
C.Reconstruct the RAID by determining stripe size and order, then combine the images
D.Use PhotoRec to carve files from raw images
AnswerC

RAID 0 stores data in fixed-size stripes (also called chunks) that are interleaved across the member disks, so reconstructing the logical volume requires knowing two critical parameters: the stripe/chunk size (e.g., 64 KiB, 128 KiB) and the exact order of disks in the RAID set. These parameters are found in the RAID metadata (md superblock, DDF, Intel RST, etc.) present on each disk or can sometimes be inferred from filesystem geometry. Once the stripe size and disk order are determined, the forensic examiner must interleave the data from each disk image at the appropriate byte offsets—combining them in a way that preserves the original block sequence. Only after this de-interleaving can the reconstructed image be parsed by tools like FTK Imager or X-Ways to access the logical filesystem.

Why this answer

RAID 0 uses striping to distribute data across multiple disks, so a logical acquisition of the array will appear interleaved without the stripe parameters. To properly assemble the image, the investigator must determine the stripe size and the order of the disks, then combine the raw images accordingly. This reconstruction ensures the data is read in the correct sequence, allowing file system analysis tools to interpret the logical volume correctly.

Exam trap

The trap here is that candidates assume a logical acquisition of a RAID array will automatically yield a usable image, but they overlook the need to reconstruct the stripe order and size to resolve the interleaved data.

How to eliminate wrong answers

Option A is wrong because EnCase does not natively mount RAID volumes; it acquires disks as raw images, and the investigator would still need to manually reconstruct the stripe parameters. Option B is wrong because simply reordering disk images alphabetically does not account for the stripe size or the correct interleave pattern, resulting in corrupted data. Option D is wrong because PhotoRec is a file carving tool that recovers files based on headers and footers, but it cannot reassemble a striped RAID array; it would only recover fragmented files from the interleaved data.

14
MCQeasy

A forensic analyst finds a partition that uses the Master Boot Record (MBR) scheme. Which of the following is TRUE about the MBR partition table?

A.It uses a 128-bit Globally Unique Identifier (GUID) for partitions
B.It supports disks larger than 2 TiB
C.It stores partition information in a 64-byte table
D.It stores a backup partition table at the end of the disk
AnswerC

In the first sector, offset 446 contains the MBR's 64-byte partition table, which is exactly four 16-byte entries. Each entry encodes the bootable flag, CHS start/end addresses, an 8-bit partition type, and 32-bit LBA start and size fields. This fixed 64-byte table is the definitive MBR structure, making this statement the correct identifying feature.

Why this answer

The MBR partition table is exactly 64 bytes in size, divided into four 16-byte entries. Each entry stores the starting and ending CHS/LBA addresses, partition type, and boot flag. This fixed-size table is the defining characteristic of the MBR scheme, limiting it to four primary partitions.

Exam trap

The trap here is that candidates confuse MBR's fixed 64-byte table with GPT's GUID-based entries, or assume MBR supports large disks because modern OSes can still read them, ignoring the 2 TiB addressing limit.

How to eliminate wrong answers

Option A is wrong because MBR uses a 32-bit partition type identifier (byte at offset 4 of each entry), not a 128-bit GUID; GUID Partition Table (GPT) uses GUIDs. Option B is wrong because MBR uses 32-bit LBA addresses, limiting the maximum addressable disk size to 2 TiB (2^32 × 512 bytes); GPT supports larger disks. Option D is wrong because MBR does not store a backup partition table; GPT stores a backup at the end of the disk for redundancy.

15
Multi-Selecteasy

Which TWO of the following are examples of file carving tools? (Select two.)

Select 2 answers
A.WinPmem
B.FTK Imager
C.PhotoRec
D.Foremost
E.dd
AnswersC, D

PhotoRec is a legitimate file carving tool developed by Christophe Grenier as part of the TestDisk suite. It scans raw disk images or partitions by reading data block by block and matching known file signatures to reconstruct files independent of the filesystem metadata. It is especially effective for recovering photos and other multimedia from formatted or damaged media, making it a correct answer to the question.

Why this answer

PhotoRec (C) is a file-carving tool that recovers files by scanning raw disk or image data for known file signatures and reconstructing content without relying on filesystem metadata. Foremost (D) is likewise a signature-based carving utility originally developed for law enforcement that recovers files from disk images and unallocated space using header/footer patterns. WinPmem (A) is a memory acquisition tool, not a carving tool, so it does not belong.

FTK Imager (B) is primarily a forensic imaging and preview tool rather than a file carver. dd (E) is a low-level bit-stream imaging/copying utility, not a carving tool.

Exam trap

The CHFI exam often tests the distinction between acquisition/imaging tools (like dd, FTK Imager, WinPmem) and file carving tools (like PhotoRec, Foremost), so candidates mistakenly select tools that create forensic images or capture memory instead of those that recover files from raw data.

16
MCQmedium

During a forensic investigation of a hard disk, the investigator finds that the partition table is missing. The disk was previously partitioned using GPT. Which area of the disk should be examined to recover the GPT partition table?

A.Last sector of the disk
B.Volume boot record
C.Master Boot Record (LBA 0)
D.LBA 1 (sector 1)
AnswerD

The primary GPT header is stored at LBA 1 (sector 1), immediately following the protective MBR at LBA 0. This header contains the disk GUID, the location of the partition entry array (typically LBA 2–33), entry counts, CRC32 integrity checks, and pointers to the backup GPT at the last sector. Because the GPT layout specifically starts here, LBA 1 is the correct answer.

Why this answer

In GPT (GUID Partition Table) disks, the primary partition table is stored in LBA 1 (sector 1), immediately following the protective MBR at LBA 0. When the partition table is missing, examining LBA 1 allows recovery of the GPT header, which contains pointers to the partition entry array. This is the correct location because GPT uses LBA 1 for its header, not the last sector or the MBR.

Exam trap

The CHFI exam often tests the misconception that the GPT partition table is stored in the MBR (LBA 0) or the last sector, but the primary GPT header is specifically at LBA 1, while the backup is at the last sector.

How to eliminate wrong answers

Option A is wrong because the last sector of the disk stores the secondary (backup) GPT header, not the primary partition table; while it can be used for recovery, the question asks for the area to examine to recover the primary GPT partition table, which is not the last sector. Option B is wrong because the Volume Boot Record (VBR) is located within a partition (e.g., at the start of a volume) and contains boot code and BPB for that volume, not the GPT partition table. Option C is wrong because LBA 0 (Master Boot Record) in a GPT disk contains only a protective MBR (to prevent legacy tools from misidentifying the disk as unpartitioned) and does not store the GPT partition table itself.

17
Multi-Selecteasy

Which TWO of the following are commonly used tools for file carving (recovering files based on file signatures)? (Select TWO.)

Select 2 answers
A.Nmap
B.Foremost
C.Wireshark
D.John the Ripper
E.Scalpel
AnswersB, E

Foremost is a mature file carving tool originally developed by the U.S. Air Force Office of Special Investigations. It scans raw disk images or memory dumps for known file header and footer signatures defined in its configuration file, then extracts contiguous blocks that match those boundaries. This signature-based method allows recovery of files from unallocated clusters without relying on the operating system's file system metadata.

Why this answer

Foremost (B) is a classic file-carving tool originally developed for the U.S. Air Force OSI that scans raw disk images or unallocated space and reconstructs files by matching known file headers, footers, and internal structures defined in its configuration file (foremost.conf). Scalpel (E) is a high-performance carving tool derived from Foremost that uses a configurable header/footer signature database (scalpel.conf) to extract files from disk images, making it a standard choice for signature-based recovery.

Nmap (A) is a network port scanner and host-discovery tool, not a file-carving utility. Wireshark (C) is a network protocol analyzer that captures and inspects packet data, not files on storage media. John the Ripper (D) is a password-cracking tool that tests hashes against wordlists and rules, which is unrelated to recovering files by their signatures.

Exam trap

The CHFI exam often tests the distinction between network analysis tools (Nmap, Wireshark) and forensic recovery tools (Foremost, Scalpel), leading candidates to mistakenly select tools they recognize from other domains.

18
Multi-Selectmedium

Which TWO of the following are Volatility plugins used for process enumeration? (Select two.)

Select 2 answers
A.pslist
B.netscan
C.pstree
D.mftparser
E.hashdump
AnswersA, C

pslist is correct because it enumerates active processes by traversing the doubly linked list of EPROCESS structures anchored at PsActiveProcessHead. This plugin reads each EPROCESS entry directly from kernel memory, extracting the process ID, parent process ID, thread counts, and creation time. It is a fundamental process listing plugin in Volatility, though it can miss processes that have been deliberately unlinked from the list to evade detection.

Why this answer

pslist (A) is a Volatility plugin that walks the active process list from the kernel's EPROCESS linked list (via PsActiveProcessHead) and prints each running process with its PID, PPID, and start time, making it a core process-enumeration plugin. pstree (C) is also a process-enumeration plugin: it uses the same process data but renders it as a parent/child tree based on PPID relationships, which helps reveal process ancestry and hidden or orphaned processes. The other options serve different forensic purposes: netscan (B) enumerates network sockets and connections, mftparser (D) parses the MFT to recover file-system metadata, and hashdump (E) extracts password hashes from the SAM registry hive, so none of them are process-enumeration plugins.

Exam trap

The EC-CHFI exam often tests the distinction between process enumeration plugins (pslist, pstree) and other Volatility plugins that serve different forensic purposes, such as network or file system analysis, to catch candidates who confuse plugin categories.

19
MCQhard

An analyst is investigating a Linux system that used ext4. The suspect deleted several files and then ran 'fstrim' on the partition. Which of the following best describes the challenge in recovering the deleted data?

A.The ext4 journal will automatically purge the metadata of deleted files
B.Data recovery is still possible using file carving because fstrim only affects free space
C.The inodes are overwritten immediately, making recovery impossible
D.The TRIM command instructs the SSD to permanently erase the blocks, and wear leveling may also have moved data
AnswerD

The TRIM command is an ATA interface primitive that informs the SSD which Logical Block Addresses are no longer in use, allowing the controller to erase the corresponding NAND flash blocks in the background, permanently destroying the data they contain. When an ext4 filesystem is mounted with the discard option or when fstrim is run, all freed blocks are trimmed, including those formerly occupied by deleted files. Additionally, the SSD's wear-leveling algorithm continuously remaps logical to physical blocks, so even if a forensic tool reads the logical LBA, the physical block that originally stored the data may have been relocated during garbage collection. This combination of block erasure and physical address remapping makes traditional file recovery impossible on such systems.

Why this answer

D is correct because the `fstrim` command sends the ATA TRIM (or SCSI UNMAP) command to the SSD, which instructs the drive to physically erase the blocks that are marked as free in the file system. This makes the original data unrecoverable at the block level, as the SSD's firmware permanently discards the data. Additionally, wear leveling may have already moved the data to different physical blocks before the TRIM command, further complicating recovery.

Exam trap

EC-Council CHFI often tests the misconception that `fstrim` only affects free space metadata or that file carving can still recover data after a TRIM, when in fact the TRIM command causes the SSD to physically erase the data blocks, making recovery impossible at the file system level.

How to eliminate wrong answers

Option A is wrong because the ext4 journal does not automatically purge metadata of deleted files; it only logs metadata changes for crash recovery, and the journal entries are overwritten in a circular fashion, not purged on deletion. Option B is wrong because file carving relies on data still being present on the storage medium, but `fstrim` on an SSD causes the blocks to be physically erased, so the data is no longer available for carving. Option C is wrong because inodes are not overwritten immediately upon deletion in ext4; they are marked as free but the data blocks remain until overwritten, and the TRIM command is what makes recovery impossible, not immediate inode overwriting.

20
MCQmedium

During a forensic examination of an SSD, the analyst notes that TRIM is enabled. What challenge does TRIM pose for data recovery?

A.TRIM reduces the lifespan of the SSD by excessive writes
B.TRIM compresses data, altering forensic signatures
C.TRIM encrypts data, preventing forensic access
D.TRIM permanently erases deleted data at the block level, hindering recovery
AnswerD

TRIM permanently erases deleted data at the block level by having the OS issue ATA DATASET MANAGEMENT or NVMe Deallocate commands that unmap the blocks containing the deleted file. Once unmapped, the SSD controller no longer preserves the old data and may zero or reuse those physical blocks during garbage collection, so conventional recovery tools cannot locate the file. This is why TRIM-implementing SSDs present a much greater forensic recovery challenge than HDDs or TRIM-disabled SSDs.

Why this answer

TRIM is an ATA command that allows the operating system to inform the SSD which data blocks are no longer in use. When TRIM is enabled, the SSD's garbage collection process immediately erases these blocks at the physical level, making the data permanently unrecoverable through conventional forensic tools. This directly hinders data recovery because the deleted data is physically zeroed or marked as invalid before any forensic acquisition can occur.

Exam trap

The trap here is that candidates confuse TRIM with wear-leveling or encryption, assuming it protects data rather than permanently destroying it, leading them to choose options that describe unrelated SSD features.

How to eliminate wrong answers

Option A is wrong because TRIM does not reduce SSD lifespan; in fact, it reduces write amplification and extends lifespan by preventing unnecessary rewrite cycles. Option B is wrong because TRIM does not compress data; it simply marks blocks as invalid for erasure, and compression is a separate file system or OS feature that does not alter forensic signatures in the context of TRIM. Option C is wrong because TRIM does not encrypt data; encryption is handled by separate mechanisms like BitLocker or hardware encryption, and TRIM operates independently of encryption.

21
MCQeasy

During a forensic investigation, an examiner wants to recover deleted files from a FAT32 file system. Which structure is most critical for file recovery?

A.File Allocation Table (FAT)
B.Master File Table (MFT)
C.Journal
D.Inode table
AnswerA

The File Allocation Table is the core metadata structure of FAT32, storing a linked list of cluster numbers (cluster chains) for every file. When a file is deleted, its directory entry is marked with byte 0xE5 but the associated FAT cluster chain is often left intact until those clusters are reused, and the directory entry still contains the starting cluster and file size. By reading the starting cluster and following the FAT chain to the end-of-chain marker, forensic tools can reassemble the deleted file's data clusters back into a contiguous stream for recovery.

Why this answer

In FAT32, the File Allocation Table (FAT) is the primary structure that tracks cluster allocation chains for files. When a file is deleted, the directory entry is marked as available, but the FAT entries (cluster chains) often remain intact until overwritten, making the FAT the most critical structure for recovering deleted files by reconstructing their cluster sequences.

Exam trap

The CHFI exam often tests the misconception that all file systems use a similar metadata structure (like MFT or inode tables), leading candidates to confuse FAT32 with NTFS or ext-based systems, when in fact FAT32 relies solely on the File Allocation Table for cluster chain recovery.

How to eliminate wrong answers

Option B (Master File Table) is wrong because MFT is specific to NTFS, not FAT32; FAT32 uses directory entries and the FAT, not an MFT. Option C (Journal) is wrong because FAT32 does not have a journaling feature; journaling is found in NTFS (USN journal) or ext3/ext4, not in FAT32. Option D (Inode table) is wrong because inode tables are used in Unix/Linux file systems like ext2/ext3/ext4, not in FAT32.

22
MCQeasy

What is slack space in a file system?

A.Space used by the file system journal
B.The unused portion of a file's last cluster
C.Space reserved for the MBR
D.Space between partitions on a disk
AnswerB

File slack, also known as cluster slack, is exactly the unused portion of the last cluster assigned to a file. When a file's logical size is not an exact multiple of the cluster size, the file system allocates a full cluster but only writes data up to the end of the file, leaving the remaining bytes in that cluster uninitialized. This residual space is significant in digital forensics because it may contain remnants of previously deleted files or other data that were not overwritten by the current file's content.

Why this answer

Slack space is the unused portion of the last cluster allocated to a file. When a file does not exactly fill its final cluster, the remaining bytes in that cluster are slack space, which can contain remnants of previously deleted data. This is a critical area in file system forensics because it may hold hidden evidence.

Exam trap

EC-Council often tests the distinction between slack space and unallocated space; the trap is that candidates confuse the unused portion of a file's last cluster (slack) with free space on the disk (unallocated), leading them to pick Option D.

How to eliminate wrong answers

Option A is wrong because the file system journal (e.g., NTFS $LogFile or ext3/4 journal) is a dedicated area for metadata changes and transaction logs, not the unused tail of a file's last cluster. Option C is wrong because the Master Boot Record (MBR) occupies the first 512 bytes of a disk (sector 0) and is a boot structure, not related to cluster-level slack. Option D is wrong because space between partitions is called partition gap or unallocated space, which exists at the disk level, not within a file's allocated cluster.

23
Multi-Selecteasy

An analyst is preparing to analyze a RAID 5 array of three disks. The analyst wants to reconstruct the logical volume for file system analysis. Which THREE steps are essential in this process?

Select 3 answers
A.Use a tool like `mdadm` (Linux) or RAID reconstructor (Windows) to assemble the array
B.Zero out the first sector of each disk to remove remnants of previous arrays
C.Determine the disk order and stripe size
D.Identify the parity rotation method (left-symmetric, etc.)
E.Run `chkdsk` on each individual disk before reconstruction
AnswersA, C, D

RAID 5 forensic analysis requires rebuilding the logical volume from the member disk images; `mdadm` can assemble the array by reading on-disk superblocks, while tools like RAID Reconstructor automate the cross-drive stripe and parity calculation. Simply imaging each disk separately leaves the filesystem fragmented across all three drives, so the examiner must first combine the disks into a coherent logical device before mounting or parsing the filesystem for evidence.

Why this answer

The essential first step is to assemble the RAID 5 set from the member disks using a tool such as mdadm on Linux or a RAID reconstructor on Windows, because the logical volume must be presented to the OS before file system analysis can occur (A). Before assembly, the analyst must determine the disk order and stripe (chunk) size, since RAID 5 distributes data across all members in a specific sequence and wrong parameters yield an unreadable volume (C). The analyst must also identify the parity rotation method (e.g., left-symmetric, right-asymmetric), because parity placement determines how each stripe's data and parity blocks are arranged and must match the original configuration (D).

Zeroing the first sector (B) is destructive and unnecessary, as it would erase metadata needed for reconstruction, and running chkdsk on individual member disks (E) is invalid because each disk holds only fragments of the file system, not a complete volume.

Exam trap

EC-Council often tests the misconception that you must run file system repair tools (like `chkdsk`) on individual disks before reconstruction, but this is incorrect because those tools require a logical volume and can corrupt the RAID metadata.

24
MCQmedium

A forensic investigator is analyzing a USB drive formatted with FAT32 and finds that a deleted file's directory entry still exists but the first character of the filename is replaced with 0xE5. What does this indicate?

A.The file is marked as hidden
B.The file has been deleted
C.The file is encrypted
D.The file is fragmented
AnswerB

When a file is deleted in a FAT file system, the first character of its 8.3 directory entry is overwritten with 0xE5, which is the standard deletion marker. This byte serves as a tombstone so the operating system knows the entry is free for new file allocation while the remaining cluster chain and directory fields stay intact until reused. Forensic analysts rely on this marker to identify deleted files and recover data by parsing the rest of the entry, including the starting cluster value and file size, making 0xE5 a direct indicator of prior deletion.

Why this answer

In FAT32 file systems, when a file is deleted, the first byte of its directory entry's filename is replaced with the hexadecimal value 0xE5 (which displays as a lowercase sigma 'σ' in some viewers). This is the standard deletion marker for FAT file systems, indicating that the file's directory entry is available for reuse. The presence of 0xE5 in the first character position specifically signifies deletion, not any other attribute or state.

Exam trap

Candidates often confuse the 0xE5 deletion marker with file attribute flags (e.g., hidden, system). In FAT32, 0xE5 in the first character of the filename indicates deletion, not a file attribute. Attribute bytes are separate in the directory entry.

How to eliminate wrong answers

Option A is wrong because the hidden attribute is controlled by a specific bit in the file attribute byte (bit 1, value 0x02) within the directory entry, not by overwriting the first character of the filename with 0xE5. Option C is wrong because FAT32 does not support native file encryption; encryption would be handled by an external tool or the OS (e.g., EFS on NTFS) and would not be indicated by a 0xE5 marker. Option D is wrong because fragmentation is a condition where a file's clusters are non-contiguous, tracked in the FAT table via cluster chains, and is not indicated by the 0xE5 byte in the directory entry.

25
MCQeasy

A forensic analyst is examining a Windows 10 system and needs to view the Master File Table ($MFT) to identify recently deleted files. Which tool is most appropriate for parsing the $MFT directly?

A.Wireshark
B.John the Ripper
C.EnCase
D.Nmap
AnswerC

EnCase is a full forensic suite that acquires bit-for-bit images and exposes the underlying NTFS structures, including the Master File Table ($MFT), $LogFile, and $UsnJrnl, so an examiner can recover active and deleted files along with their timestamps, sizes, and parent paths. It performs file carving and signature analysis to reconstruct data from unallocated clusters, and it parses $MFT resident and non-resident data attributes to reassemble fragmented or partially overwritten records. This makes EnCase the appropriate choice when the goal is to examine and recover deleted artifacts from a Windows 10 system.

Why this answer

EnCase is a forensic suite that includes a dedicated parser for the Master File Table ($MFT) on NTFS volumes. It can directly read the raw $MFT file to recover metadata of deleted files, including their names, timestamps, and data runs, even after the directory entry is removed. This makes it the correct choice for examining the $MFT to identify recently deleted files.

Exam trap

EC-CHFI often tests the distinction between network analysis tools (Wireshark, Nmap) and password crackers (John the Ripper) versus forensic file system parsers, leading candidates to pick a familiar tool name without considering its actual function.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects packets on a network interface; it has no capability to parse local file system structures like the $MFT. Option B is wrong because John the Ripper is a password cracking tool that operates on hash files (e.g., /etc/shadow or LM/NT hashes), not on file system metadata or the $MFT. Option D is wrong because Nmap is a network scanning utility used for host discovery and port enumeration; it cannot read or interpret the $MFT on a local drive.

26
Multi-Selectmedium

Which TWO of the following are valid methods to hide data on an NTFS file system without using external tools?

Select 2 answers
A.Embedding data in file slack space
B.Storing data in the NTFS file system journal ($LogFile)
C.Using the $Volume attribute in the MFT
D.Encrypting data with EFS
E.Using Alternate Data Streams (ADS)
AnswersA, E

File slack is unused space at the end of a cluster that can be filled with data.

Why this answer

A is correct because file slack space is the unused bytes between the end of a file's logical data and the end of its allocated cluster. On NTFS, when a file does not fill its last cluster, the remaining bytes (RAM slack and drive slack) can be written to without affecting the file's visible content. This is a native hiding method that requires no external tools, as the data is simply written to the slack region using standard file I/O operations.

Exam trap

EC-CHFI often tests the misconception that NTFS journals or MFT attributes can be used for data hiding without external tools, but only slack space and Alternate Data Streams (ADS) are native, supported mechanisms that do not require third-party utilities.

27
MCQmedium

An investigator is analyzing a FAT32 drive and notices that a deleted file's directory entry still exists, but the first byte of the filename is changed to 0xE5. What does this indicate about the file?

A.The file is fragmented
B.The file is marked as deleted but its data clusters may still be intact
C.The file has been securely overwritten
D.The file is encrypted
AnswerB

In FAT32, a file deletion changes the first byte of its directory entry to 0xE5, signaling that the entry is available for reuse, while the clusters linked in the FAT are marked as free. The actual data bytes remain in the volume until overwritten by new writes, so deleted files can often be recovered using forensic carving or FAT chain analysis. This makes 0xE5 a critical artifact for identifying recoverable evidence.

Why this answer

In FAT32 file systems, a deleted file's directory entry is marked by replacing the first byte of the filename with 0xE5. This indicates the file is logically deleted, but the data clusters referenced in the directory entry remain intact until overwritten by new data. Option B is correct because the 0xE5 marker is the standard FAT deletion marker, and the clusters are not erased.

Exam trap

The trap here is that candidates may confuse the 0xE5 deletion marker with fragmentation or assume the data is securely erased, when in fact the marker only indicates logical deletion and the clusters remain intact.

How to eliminate wrong answers

Option A is wrong because fragmentation is indicated by the FAT chain entries showing non-contiguous cluster numbers, not by the 0xE5 byte in the directory entry. Option C is wrong because secure overwriting would zero out or randomize the data clusters, but the 0xE5 marker only indicates logical deletion without modifying cluster content. Option D is wrong because encryption is a property of the file's data content or metadata, not indicated by the first byte of the filename being changed to 0xE5.

28
MCQhard

An analyst discovers that a Windows system has hidden data in the Host Protected Area (HPA) of the hard drive. Which tool or method can be used to detect and access the HPA?

A.Using the Windows Disk Management utility
B.Using the hdparm command in Linux with the -N flag
C.Using the Volatility framework
D.Using the chkdsk command
AnswerB

hdparm -N /dev/sda shows the user-accessible capacity vs. native capacity, revealing HPA.

Why this answer

The Host Protected Area (HPA) is a reserved region on ATA/ATAPI hard drives that is not visible to the operating system's standard disk utilities. The `hdparm` command in Linux with the `-N` flag is specifically designed to detect and modify the HPA by querying the drive's native max address, revealing hidden sectors. Windows Disk Management and other OS-level tools cannot access the HPA because it is hidden at the firmware level via the ATA SET MAX ADDRESS command.

Exam trap

The trap here is that candidates assume standard Windows utilities like Disk Management can see all drive areas, but the HPA is hidden at the firmware level and requires ATA command-level tools like hdparm to access.

How to eliminate wrong answers

Option A is wrong because Windows Disk Management only shows partitions visible to the OS and cannot detect the HPA, which is hidden at the ATA command level. Option C is wrong because the Volatility framework is a memory forensics tool for analyzing RAM dumps, not for low-level hard drive regions like the HPA. Option D is wrong because chkdsk checks file system integrity on visible partitions and has no capability to interact with ATA commands that control the HPA.

29
MCQmedium

A forensic investigator recovers a hard drive from a suspect's computer. The drive is detected as 120 GB in BIOS, but forensic tools report only 100 GB of addressable space. Which data hiding technique is MOST likely being used?

A.Device Configuration Overlay (DCO)
B.Volume slack
C.Host Protected Area (HPA)
D.Alternate Data Streams (ADS)
AnswerC

Host Protected Area (HPA) is an ATA feature that uses the SET MAX ADDRESS command to lower the drive's reported maximum address, causing all sectors beyond that boundary to become inaccessible to the operating system and BIOS. This effectively hides data in the protected area at the end of the physical disk, which is exactly the kind of capacity mismatch that forensic acquisition tools detect by comparing the native maximum address against the current maximum. HPA is the correct answer because it directly addresses the hardware-level capacity reduction described.

Why this answer

The Host Protected Area (HPA) is a region on a hard drive that is hidden from the operating system by using the ATA SET MAX ADDRESS command to reduce the reported addressable space. Since the BIOS detects the full 120 GB but forensic tools see only 100 GB, the HPA is the most likely technique, as it creates a hidden area beyond the reported maximum LBA that is not visible to standard forensic acquisition tools unless specifically addressed.

Exam trap

The trap here is that candidates confuse HPA with DCO, but the key differentiator is that DCO hides space from the BIOS as well, while HPA allows the BIOS to see the full drive but hides space from the OS and forensic tools.

How to eliminate wrong answers

Option A is wrong because Device Configuration Overlay (DCO) is a feature that allows the drive manufacturer to hide the entire drive or a portion of it from the BIOS and OS, but here the BIOS correctly detects 120 GB, ruling out DCO. Option B is wrong because volume slack refers to unused space at the end of a volume that is not part of any partition, but it does not reduce the total addressable space reported by forensic tools; it is a byproduct of partition alignment, not a deliberate hiding technique. Option D is wrong because Alternate Data Streams (ADS) are a feature of NTFS that allow data to be hidden within a file's metadata, but they do not affect the total addressable space of a hard drive; they operate at the file system level, not the disk geometry level.

30
MCQmedium

An investigator needs to analyze the contents of the Windows Recycle Bin on a system running Windows 10. Which artifact(s) should the investigator examine to determine the original location and deletion time of a file in the Recycle Bin?

A.The 'System Volume Information' folder
B.The '$I' and '$R' files in the $Recycle.Bin\<SID> folder
C.The 'INFO2' file in the Recycled folder
D.The 'desktop.ini' file in the Recycle Bin
AnswerB

In Windows 10, deleted files are stored under C:\$Recycle.Bin\<UserSID> as a pair of files with a shared random suffix: the $I file contains a binary structure—8-byte header, original file size, 64-bit FILETIME deletion timestamp, UTF-16 original path length, and the original absolute path—while the $R file retains the raw contents of the deleted object. Because the visible $R filename is a generated suffix, parsing the $I metadata is the only way to recover the original name and location; both files together allow full forensic reconstruction of the deletion.

Why this answer

In Windows 10, the Recycle Bin is implemented as the `$Recycle.Bin` folder, with each user having a subfolder identified by their Security Identifier (SID). When a file is deleted, it is renamed to an `$R` file (the actual data) and an `$I` file (metadata including original path and deletion timestamp) is created. Examining these `$I` and `$R` files allows the investigator to determine the original location and deletion time of the file.

Exam trap

EC-Council often tests the distinction between Windows 10's `$Recycle.Bin` folder with `$I`/`$R` files and the legacy `Recycled` folder with `INFO2` file, so candidates mistakenly choose the `INFO2` option for modern Windows systems.

How to eliminate wrong answers

Option A is wrong because the 'System Volume Information' folder contains system restore points and volume shadow copies, not Recycle Bin metadata. Option C is wrong because the 'INFO2' file is used in older Windows versions (Windows 2000/XP) for Recycle Bin metadata, not in Windows 10. Option D is wrong because 'desktop.ini' is a configuration file that controls folder appearance (e.g., icon layout), not a forensic artifact for file deletion details.

31
MCQmedium

A forensic analyst is examining a USB drive formatted with FAT32. A suspect claims they deleted a file several weeks ago. The analyst uses a carving tool but cannot recover the file. What is the MOST likely reason for the failed recovery?

A.The file was encrypted and cannot be carved
B.FAT32 does not support file carving
C.The file was stored in the MFT, which is only present in NTFS
D.The file clusters were overwritten by new data
AnswerD

File carving succeeds only when the original data content still physically exists on the media, typically in unallocated space. If the drive continued to be used after the file was deleted, the clusters that once held the file may have been reallocated and overwritten with new data. Overwriting destroys the original byte pattern, so there is nothing left for carving algorithms to recover. This is the correct reason a file may be un-carveable even though carving itself remains possible.

Why this answer

File carving relies on finding the file's content clusters on disk, typically by scanning for file headers and footers. If the suspect deleted the file weeks ago, the clusters that held the file's data were likely marked as free in the FAT32 file allocation table and subsequently overwritten by new data written to the drive. This is the most common reason for carving failure on a FAT32 volume that has been in active use after deletion.

Exam trap

EC-Council often tests the misconception that file carving depends on file system metadata (like MFT or directory entries), when in fact carving works at the raw data level and fails primarily due to data overwriting.

How to eliminate wrong answers

Option A is wrong because encryption does not prevent file carving; carving recovers raw data clusters regardless of encryption, though the recovered data would be unreadable without the key. Option B is wrong because FAT32 fully supports file carving; carving tools work at the raw sector level and are file-system agnostic, relying on file signatures rather than file system metadata. Option C is wrong because the MFT (Master File Table) is a metadata structure specific to NTFS, not FAT32; FAT32 uses directory entries and FAT tables, not an MFT, so the file's metadata would be in a directory entry, not the MFT.

32
MCQmedium

A security analyst examines a compromised Windows server and finds a file named 'readme.txt' that appears legitimate. However, using `dir /r`, they discover an alternate data stream named 'readme.txt:hidden.exe'. What is the most likely purpose of this alternate data stream?

A.It is a backup copy of the file
B.It is a symbolic link to another file
C.It is a malicious executable hidden in the file
D.It is a log file generated by the operating system
AnswerC

This is the most plausible finding because NTFS Alternate Data Streams are a well-known technique for concealing malicious payloads on a compromised Windows host. An attacker can write an executable into a stream of a benign file (e.g., `type evil.exe > report.txt:evil.exe`) and execute it using tools like PowerShell or `wmic`, allowing it to evade basic directory scanning and security software that only checks the primary data stream. On a server that is known to be compromised, an unrecognized executable stream is a strong indicator of malware persistence or lateral movement.

Why this answer

Alternate data streams (ADS) in NTFS allow a malicious executable to be hidden within a legitimate file without affecting its visible size or content. The `dir /r` command reveals the ADS 'readme.txt:hidden.exe', indicating that an executable is attached to the file, which is a common technique to evade detection and execute malware.

Exam trap

The CHFI exam often tests the misconception that ADS are used for legitimate system functions like backups or logs, but the key is that ADS are a hiding mechanism for malicious content, not a standard feature for those purposes.

How to eliminate wrong answers

Option A is wrong because ADS are not used for backup copies; backups typically use file extensions or separate directories, not hidden streams. Option B is wrong because symbolic links are separate file system objects created with `mklink`, not hidden within an ADS. Option D is wrong because ADS are not standard log file locations; Windows logs are stored in dedicated directories like `%SystemRoot%\System32\winevt\Logs`.

33
MCQhard

An investigator images an SSD that has TRIM enabled. Which of the following challenges will MOST likely affect the recovery of deleted files from this SSD?

A.The SSD uses a different partition table scheme
B.TRIM causes the SSD to zero out freed blocks, preventing recovery
C.The SSD firmware encrypts all data, requiring a decryption key
D.Wear leveling spreads data across blocks, complicating recovery
AnswerB

TRIM is an ATA command that tells the SSD which logical blocks belonging to a deleted file are no longer in use, causing the controller to immediately discard or erase that data at the flash level. As a result, the original content is physically removed or marked for garbage collection before a forensic image is taken, so common recovery tools cannot reconstruct the file. This direct erasure is what makes deleted data unrecoverable on a TRIM-enabled SSD.

Why this answer

When TRIM is enabled on an SSD, the operating system notifies the drive which blocks are no longer in use. The SSD's firmware then immediately zeroes out or internally marks those blocks as free, physically erasing the data. This prevents forensic tools from recovering deleted files because the underlying data is no longer present on the NAND flash cells.

Exam trap

The trap here is that candidates often confuse wear leveling with TRIM, assuming that wear leveling itself causes data loss, when in fact TRIM is the specific command that actively erases freed blocks on SSDs.

How to eliminate wrong answers

Option A is wrong because the partition table scheme (e.g., MBR vs. GPT) does not affect the ability to recover deleted files from an SSD with TRIM; TRIM operates at the block level, independent of the partition layout. Option C is wrong because while some SSDs support hardware encryption, it is not a default or universal feature, and TRIM itself does not cause encryption; the question specifically states TRIM is enabled, not that the drive is encrypted.

Option D is wrong because wear leveling spreads writes across blocks to extend the drive's lifespan, but it does not actively erase or zero out freed blocks; TRIM is the mechanism that causes data loss, not wear leveling.

34
MCQmedium

An analyst is examining a hard drive that was seized from a suspect. The drive is detected as a smaller capacity than listed on the label. Which of the following is the MOST likely explanation?

A.The drive has been partitioned with a GPT table, which does not use the full capacity
B.The file system is FAT32, which has a 2 TB limit
C.The drive controller has a firmware bug reporting incorrect size
D.The drive has a Host Protected Area (HPA) that hides sectors from the OS
AnswerD

A Host Protected Area (HPA) is an ATA feature that allows the maximum LBA address to be set to a value lower than the drive's physical limit, effectively hiding the sectors beyond that point from the operating system. This is performed with the SET MAX ADDRESS command, and the hidden area can contain data deliberately hidden from normal access. Forensic examiners can determine the true native capacity using ATA commands and, with proper write-blocking, remove the HPA to image the entire disk, making this the correct explanation for the observed discrepancy.

Why this answer

A Host Protected Area (HPA) is a reserved region on an ATA/ATAPI hard drive that can hide sectors from the operating system, making the drive appear smaller than its physical capacity. This is a common anti-forensics technique used to conceal data, and it can be detected and removed using tools like hdparm or ATA Security commands.

Exam trap

The trap here is that candidates may confuse file system limits (like FAT32's 2 TB cap) with raw drive capacity reporting, or assume partitioning schemes like GPT inherently reduce capacity, when in fact HPA is the deliberate, forensically significant mechanism for hiding sectors.

How to eliminate wrong answers

Option A is wrong because GPT (GUID Partition Table) actually supports drives larger than 2 TB and uses the full capacity; it does not hide sectors or reduce usable space. Option B is wrong because FAT32 has a 2 TB volume size limit, but this applies to the file system, not the raw drive capacity detected by the BIOS or OS; the drive would still report its full physical size. Option C is wrong while firmware bugs can cause incorrect size reporting, they are rare and not the most likely explanation in a forensic context; HPA is a deliberate, common mechanism for hiding data.

35
Multi-Selectmedium

An analyst is examining a Windows 10 system and suspects the use of NTFS alternate data streams (ADS) to hide malicious executables. Which THREE methods can the analyst use to detect hidden ADS on the system?

Select 3 answers
A.Checking the $MFT for $DATA attributes where the attribute name is not empty
B.Using `Sysinternals streams.exe` to enumerate streams on the drive
C.Comparing file sizes from `dir` output with raw disk sector counts
D.Running `sfc /scannow` to verify system file integrity
E.Running `dir /r` in the command prompt to list files with alternate streams
AnswersA, B, E

In NTFS, every file has a default, unnamed $DATA attribute that holds the primary file content; any additional $DATA attribute must have a non-empty name and constitutes an alternate data stream (ADS). Parsing the MFT directly, using forensic tools or a custom parser, reveals these named $DATA attributes even when the file system APIs hide them from normal directory listings. This method is definitive because it reads the raw on-disk structures rather than relying on OS-level enumeration, and it can expose ADS that were deliberately created with names mimicking legitimate files.

Why this answer

Option A is correct because NTFS alternate data streams are stored as additional $DATA attributes within a file's MFT record, so parsing the $MFT and looking for $DATA attributes whose name field is non-empty directly reveals the existence of named streams. Option B is correct because Sysinternals streams.exe is purpose-built to enumerate NTFS alternate data streams on files, directories, or entire drives, making it a standard forensic and administrative detection tool. Option E is correct because the Windows `dir /r` switch displays alternate data streams associated with files, listing each stream name and its size alongside the normal file listing.

Option C is not a reliable detection method because `dir` reports the logical file size while raw sector counts include allocation and metadata differences, so discrepancies do not specifically indicate ADS. Option D is incorrect because `sfc /scannow` only verifies and repairs the integrity of protected Windows system files and does not enumerate or report alternate data streams.

Exam trap

Candidates often mistakenly believe that `dir /r` is only available in PowerShell or is not a valid method. In reality, `dir /r` works in the standard Windows Command Prompt (cmd.exe) and is a legitimate way to list alternate data streams.

36
MCQmedium

A Linux system uses the ext4 filesystem. A forensic analyst needs to recover a recently deleted file. Which of the following methods is MOST likely to succeed if the file's inode has not been reallocated?

A.Mount the filesystem with `mount -o ro,noatime` and browse
B.Use `dd` to copy the entire partition and search for the file signature
C.Use `ls -la` to view deleted file entries
D.Run `extundelete /dev/sda1 --restore-file /path/to/file`
AnswerD

Running extundelete /dev/sda1 --restore-file /path/to/file is correct because extundelete is specifically built to recover deleted files from ext3/ext4 filesystems by scanning inode tables, block bitmaps, and the journal to locate the inode and reconstruct the file's data blocks. It can operate on a live mounted partition, but safest practice is to unmount first, and it restores the original filename in a dedicated output directory if the inode is still present and not overwritten. This targeted approach aligns with ext4's metadata structures, unlike simple browsing or blind carving.

Why this answer

`extundelete` is a dedicated tool designed to recover deleted files from ext3/ext4 filesystems by leveraging the filesystem's journal and inode data. If the inode has not been reallocated, the tool can directly restore the file using its path, making it the most targeted and efficient method.

Exam trap

EC-Council often tests the misconception that deleted files remain visible in directory listings or can be recovered by simply mounting the filesystem, when in fact specialized tools like `extundelete` are required to access the filesystem's metadata structures.

How to eliminate wrong answers

Option A is wrong because mounting with `-o ro,noatime` only provides read-only access and prevents access time updates, but does not recover deleted files; deleted files are not visible through normal directory browsing. Option B is wrong because using `dd` to image the partition and then searching for a file signature is a brute-force, time-consuming method that relies on file content being contiguous and unoverwritten, and it is less reliable than using filesystem metadata. Option C is wrong because `ls -la` only lists current directory entries and cannot show deleted file entries; deleted files are not listed in the directory structure.

37
MCQhard

During a memory forensics analysis using Volatility, an examiner runs 'python vol.py -f memory.dmp pslist' and sees a suspicious process named 'expl0rer.exe' with a PPID of 4. What does a PPID of 4 indicate, and what should the examiner do next?

A.The process is probably a hidden or injected process; run 'psxview' and 'malfind' to detect anomalies
B.The process is a child of the System process, indicating it is a legitimate system process; no further action needed
C.The process is a child of the System Idle Process, which is normal; ignore it
D.The process has been injected into the System process and is likely a rootkit; run 'psscan' to verify
AnswerA

In Volatility, a process whose parent PID is 4 (System) is anomalous because the System kernel process rarely creates user-mode children; this pattern often appears when malware uses parent PID spoofing or when a process is hidden from the normal active process list. Run 'psxview' to cross-reference process listings from multiple sources (e.g., PsActiveProcessHead, PspCidTable, and CSRSS) to uncover hidden processes, and 'malfind' to locate executable pages containing injected shellcode such as an MZ header. These steps will confirm whether the process is truly malicious or merely unusual, making this the correct investigative action.

Why this answer

In Windows memory forensics, a PPID of 4 indicates the parent process is the System process (PID 4), which is the kernel-mode process responsible for starting system services and drivers. A suspicious process like 'expl0rer.exe' with PPID 4 is highly anomalous because legitimate user-mode processes are rarely direct children of the System process; the most notable legitimate exception is smss.exe. The examiner should run 'psxview' to check for hidden processes and 'malfind' to detect code injection, as this PPID can indicate a process masquerading as a system component or whose parent PID has been manipulated.

Exam trap

The CHFI exam often tests the misconception that PPID 4 always means a legitimate system process, but the trap is that the System process (PID 4) rarely has direct user-mode children, and any suspicious name warrants further analysis with 'psxview' and 'malfind'.

How to eliminate wrong answers

Option B is wrong because while PPID 4 does indicate the System process, a suspiciously named process like 'expl0rer.exe' is not a legitimate system process; system processes have standard names (e.g., smss.exe, csrss.exe) and are not direct children of PID 4. Option C is wrong because PPID 4 refers to the System process, not the System Idle Process (PID 0); the System Idle Process has PID 0, and a PPID of 4 does not indicate an idle or normal process. Option D is wrong because while injection is possible, a PPID of 4 does not necessarily mean the process has been injected into the System process; it means the process is a child of the System process, and 'psscan' is used to find terminated or hidden processes, not specifically to verify injection; 'malfind' is the appropriate tool for detecting injected code.

38
MCQmedium

In an ext4 file system, a forensic analyst needs to examine the journal to recover recently deleted files. Where is the journal typically stored?

A.In a reserved area after the superblock
B.In the superblock
C.In a special inode (inode 8)
D.In the group descriptor table
AnswerC

In ext4, the default journal is stored as a special inode, typically inode 8. This inode is allocated when the filesystem is created with a journal, and it contains the journal blocks that record metadata and data changes for recovery. The superblock's s_journal_inum field points to this inode number, confirming its role. The journal inode is not a regular file; it is marked as a special filesystem object, and its data blocks are used exclusively for journaling.

Why this answer

In ext4, the journal is stored as a regular file associated with a special inode, typically inode 8. This design allows the journal to be managed by the file system's standard inode and block allocation mechanisms, rather than being placed in a fixed reserved area. When a file is deleted, its data blocks may still be referenced in the journal until they are overwritten, enabling recovery by replaying or analyzing journal entries.

Exam trap

The CHFI exam often tests the misconception that the journal is stored in a fixed reserved area (like after the superblock) rather than as a file associated with a special inode, leading candidates to choose Option A.

How to eliminate wrong answers

Option A is wrong because the reserved area after the superblock is used for the block group descriptors and backup superblocks, not for the journal; the journal is not stored in a fixed reserved area but as a file. Option B is wrong because the superblock contains metadata about the file system (e.g., block size, inode count) but does not store the journal itself; the journal is a separate data structure. Option D is wrong because the group descriptor table contains per-block-group metadata (e.g., block and inode bitmaps) and does not hold journal data; the journal is managed via a special inode.

39
MCQmedium

During a forensic investigation, you encounter a Windows system with an NTFS volume. The suspect claims they never used the recycle bin, but you find files in the $Recycle.bin folder. Which artifact can help you determine the original file path and deletion time?

A.The USN journal
B.The file slack space
C.The $I file in the $Recycle.bin folder
D.The $MFT entry for the deleted file
AnswerC

When Windows moves a file to the Recycle Bin, it creates an $I file (paired with an $R content file) in the $Recycle.Bin folder. The $I file contains a header including the file size, the deletion timestamp in Windows FILETIME format, and the original full path stored as UTF-16LE. This makes the $I file the authoritative source for determining the original path and deletion time, even if the $R file's content has been overwritten.

Why this answer

The $I file in the $Recycle.bin folder stores metadata about the deleted file, including its original file path and the deletion timestamp. When a file is moved to the Recycle Bin, Windows creates an $I file (e.g., $I<random>.dat) containing this information, which can be parsed to recover the original location and deletion time. This makes it the direct artifact for the investigator's needs.

Exam trap

The CHFI exam often tests the misconception that the $MFT entry retains deletion metadata, but in NTFS, the $MFT entry for a deleted file is marked as free and its attributes are often cleared or reused, whereas the $I file in $Recycle.bin is the persistent artifact for original path and deletion time.

How to eliminate wrong answers

Option A is wrong because the USN journal records changes to files and directories (e.g., creation, deletion, renaming) but does not store the original file path or deletion time in a directly retrievable format for Recycle Bin items; it only logs the update sequence number and basic operation type. Option B is wrong because file slack space contains residual data from previous file allocations (e.g., RAM or partial file fragments) but does not store metadata like original file paths or deletion times. Option D is wrong because the $MFT entry for the deleted file is typically marked as free and its attributes (like $FILENAME) may be overwritten or cleared, so it cannot reliably provide the original path or deletion time after the file is moved to the Recycle Bin.

40
Multi-Selecthard

Which TWO of the following are challenges in SSD forensics compared to traditional HDD forensics? (Choose two.)

Select 2 answers
A.SSDs are not compatible with forensic imaging tools
B.Wear leveling distributes data across blocks, making it harder to recover specific files
C.TRIM command causes deleted data to be erased quickly
D.SSDs have larger storage capacity than HDDs
E.SSDs are more resistant to physical damage
AnswersB, C

In order to prolong NAND flash lifespan, the SSD’s firmware uses wear leveling to dynamically remap logical block addresses across different physical memory cells, so a file's sectors are not stored contiguously or predictably in physical flash. Since the Flash Translation Layer hides the current physical location of each logical block, forensic carving tools that reconstruct files based on contiguous clusters or expected sector order are often defeated. Additionally, wear leveling may copy data to new blocks while the old block is erased, further destroying remnants of previously deleted files before the examiner ever acquires the drive.

Why this answer

Option B is correct because wear leveling is an SSD controller function that deliberately writes data to different physical NAND blocks to spread erase cycles evenly, so logical addresses no longer map predictably to physical locations and file fragments become scattered, making recovery of specific files far harder than on an HDD where LBAs map directly to fixed platters/sectors. Option C is correct because the TRIM command, issued by the OS (e.g., via ATA DATA SET MANAGEMENT or SCSI UNMAP), tells the SSD controller that deleted blocks are no longer needed, allowing garbage collection to erase them almost immediately, which destroys residual data that would otherwise remain recoverable on an HDD until overwritten. Option A is wrong because SSDs are fully compatible with standard forensic imaging tools such as dd, FTK Imager, and EnCase; the challenge is write-blocking and controller behavior, not tool compatibility.

Option D is wrong because capacity is not a forensic challenge unique to SSDs, and SSDs are not inherently larger than HDDs. Option E is wrong because physical damage resistance is not a recognized forensic challenge distinguishing SSDs from HDDs in this context.

Exam trap

EC-Council often tests the misconception that TRIM is a challenge only for deleted data recovery, but candidates must also recognize wear leveling as a separate, equally critical challenge that affects the forensic recovery of both deleted and existing files.

41
Multi-Selectmedium

Which TWO of the following are challenges specific to SSD forensics compared to traditional HDD forensics?

Select 2 answers
A.Bad sectors
B.Wear leveling
C.File fragmentation
D.TRIM command
E.Slack space
AnswersB, D

Wear levelling spreads writes across NAND blocks and relocates data transparently, so logical block addresses no longer map predictably to physical locations. This defeats the contiguous, sequential imaging assumptions that traditional HDD forensics relies upon.

Why this answer

Wear leveling (B) is a challenge specific to SSD forensics because SSDs use a flash translation layer (FTL) to remap logical block addresses (LBAs) to physical NAND pages, so the same LBA can point to different physical locations over time and data may be spread across multiple dies, making it difficult to reconstruct the true physical layout or recover prior versions of data. The TRIM command (D) is also SSD-specific: when the OS issues TRIM (e.g., via ATA DATA SET MANAGEMENT or SCSI UNMAP), the drive marks deleted LBAs as invalid and may erase or garbage-collect those blocks, so deleted data can be unrecoverable and the drive's contents change even without user activity, complicating imaging and timeline analysis. By contrast, bad sectors (A), file fragmentation (C), and slack space (E) are challenges common to traditional HDD forensics as well, since they arise from magnetic platter media, file-system allocation behavior, and cluster-level storage rather than from SSD flash management.

Exam trap

A common misconception is that TRIM is the only SSD-specific challenge, but wear leveling is equally critical because it affects data recovery of both deleted and existing files by altering physical storage locations.

42
MCQhard

A forensic examiner is analyzing a RAID 5 array consisting of three disks. One disk has failed and is not available. The remaining two disks contain data and parity. Which technique can be used to reconstruct the missing disk's data and recover the original data?

A.Replace the failed disk and rebuild the array using the controller's rebuild function
B.Use dd to image the two disks, then perform a XOR operation on the data stripes to reconstruct the third disk's data
C.Use FTK Imager to create a logical image of each disk and merge them
D.Simply image the two disks and use file carving tools to extract files
AnswerB

RAID 5 stores parity as the XOR of the data stripes across all member disks. Imaging the two surviving disks with dd, then XORing corresponding stripes, regenerates the missing disk's data, since parity XOR remaining data yields the absent block.

Why this answer

In a RAID 5 array with three disks, data and parity are striped across all disks. When one disk fails, the missing data can be reconstructed by performing an XOR operation on the corresponding stripes from the remaining two disks. This is because RAID 5 uses distributed parity where the parity block is the XOR of the data blocks in the same stripe, so XORing the surviving data and parity stripes recovers the lost data.

Exam trap

The CHFI exam often tests the misconception that RAID 5 can tolerate two disk failures or that simple imaging of surviving disks yields complete data without reconstruction, leading candidates to choose file carving or logical imaging options.

How to eliminate wrong answers

Option A is wrong because replacing the failed disk and using the controller's rebuild function is a hardware/administrative recovery method, not a forensic technique for reconstructing data from the remaining two disks when the failed disk is unavailable. Option C is wrong because FTK Imager's logical imaging merges file system metadata, not raw stripe-level data, and cannot reconstruct missing RAID 5 data without understanding the stripe layout and parity. Option D is wrong because simply imaging two disks and using file carving tools will only recover files that are contiguous and not split across stripes, and cannot reconstruct data that was solely on the failed disk.

43
MCQeasy

Which file system uses a Master File Table ($MFT) as its central catalog for file metadata?

A.FAT32
B.APFS
C.ext4
D.NTFS
AnswerD

NTFS is the correct answer because it uses the Master File Table (MFT) as its central metadata repository. The MFT is a special file containing at least one record for every file and directory, storing attributes, security descriptors, timestamps, and data runs. This central table allows NTFS to efficiently locate and manage all filesystem objects, and it is a defining feature of NTFS.

Why this answer

NTFS (New Technology File System) uses the Master File Table ($MFT) as its central catalog to store metadata about every file and directory on the volume. Each file or directory has at least one record in the $MFT, which contains attributes such as timestamps, security descriptors, data runs, and the file's name. This design is fundamental to NTFS's ability to support advanced features like journaling, hard links, and alternate data streams.

Exam trap

EC-CHFI often tests the misconception that FAT32 or ext4 uses a Master File Table because they also have file allocation tables or inode tables, but the $MFT is a unique NTFS structure with a specific on-disk format and record-based architecture.

How to eliminate wrong answers

Option A is wrong because FAT32 uses a File Allocation Table (FAT) and directory entries, not a Master File Table; it stores file metadata in 32-byte directory entries within clusters. Option B is wrong because APFS (Apple File System) uses a B-tree based container structure with object maps and snapshots, not an $MFT; its metadata is managed through a catalog file and extent reference tree. Option C is wrong because ext4 uses inodes and block groups to store file metadata, with a superblock and group descriptors, not a Master File Table; the inode table is the central metadata structure.

44
MCQeasy

A forensic investigator examines a hard drive and needs to recover deleted files. Which tool is specifically designed for file carving by scanning raw data for file headers and footers without relying on the file system?

A.Foremost
B.Volatility
C.Autopsy
D.FTK Imager
AnswerA

Foremost is a classic file-carving utility that scans raw byte streams (such as a dd or E01 image) for known file signatures—e.g., JPEG headers 0xFFD8FF, PNG, ZIP—and extracts the intervening data as a reconstructed file. Because it operates directly on unallocated space and does not depend on filesystem metadata (MFT, inodes, directory entries), it can recover deleted files no longer listed in any index. It is driven by a configuration file defining the signatures and can use internal structural hints, such as embedded length fields, to improve recovery accuracy.

Why this answer

Foremost is a file carving tool that scans raw disk data for known file headers and footers (e.g., JPEG, PDF, ZIP) to recover files independently of the file system metadata. This makes it ideal when the file system is damaged or deleted, as it relies solely on content signatures rather than directory structures.

Exam trap

The CHFI exam often tests the distinction between file carving tools (Foremost) and forensic suites (Autopsy, FTK Imager) or memory analysis tools (Volatility), trapping candidates who confuse a tool's primary function with its ancillary features.

How to eliminate wrong answers

Option B (Volatility) is wrong because it is a memory forensics framework for analyzing RAM dumps, not a file carving tool for hard drives. Option C (Autopsy) is wrong because it is a digital forensics platform that relies on file system analysis and does not perform raw file carving by default; it uses tools like Foremost as plugins. Option D (FTK Imager) is wrong because it is primarily a disk imaging and preview tool that preserves file system metadata, not a dedicated file carver that scans raw data for headers and footers.

45
MCQmedium

An analyst suspects that sensitive data was hidden in the NTFS Alternate Data Streams (ADS) of a file on a suspect's drive. Which tool is specifically designed to enumerate and extract data from ADS on a live Windows system?

A.Foremost
B.PhotoRec
C.dd
D.Streams.exe (Sysinternals)
AnswerD

Streams.exe, part of the Sysinternals suite, is the correct tool because it is specifically built to enumerate NTFS Alternate Data Streams, which are hidden metadata streams associated with files (e.g., 'file.txt:hidden.txt'). It scans the NTFS filesystem and displays the full path of each stream, including the stream name and file size, allowing an analyst to identify suspicious data hidden in ADS. This tool directly addresses the scenario of sensitive data concealed in an NTFS ADS, unlike generic carving or imaging utilities.

Why this answer

Streams.exe from Sysinternals is specifically designed to enumerate and extract data from NTFS Alternate Data Streams (ADS) on a live Windows system. It scans files and directories for hidden streams, displaying their names and sizes, and can optionally delete or extract them. This makes it the correct tool for the analyst's task.

Exam trap

EC-Council CHFI often tests the distinction between file carving tools (Foremost, PhotoRec) and tools that parse file system metadata (Streams.exe), leading candidates to mistakenly choose a carving tool for ADS enumeration.

How to eliminate wrong answers

Option A is wrong because Foremost is a file carving tool that recovers files based on headers and footers, not designed to enumerate or extract NTFS Alternate Data Streams. Option B is wrong because PhotoRec is also a file carving utility focused on recovering lost files from raw disk images, not ADS enumeration. Option C is wrong because dd is a low-level disk imaging tool that creates bit-for-bit copies of storage media; it does not parse NTFS metadata or expose ADS.

46
Multi-Selecthard

Which THREE of the following are challenges specific to SSD forensics compared to HDD forensics?

Select 3 answers
A.Garbage collection that automatically erases stale blocks
B.TRIM command causing data erasure
C.Wear leveling algorithms that relocate data
D.Platter rotation causing magnetic remanence
E.Controller-based compression reducing data size
AnswersA, B, C

Garbage collection is a background process in SSD controllers that consolidates valid data into fewer blocks and then erases entire blocks containing stale pages. Because it runs autonomously without any operating system command, it can physically erase data from deleted files before an investigator can image the drive, destroying remnants that might otherwise be recovered through file carving or chip-off analysis.

Why this answer

Option A is correct because SSD garbage collection proactively erases blocks containing stale or invalid pages in the background, so data that would remain recoverable on an HDD platter can be destroyed without any user action. Option B is correct because the TRIM command tells the SSD controller which LBAs are no longer in use, allowing those flash pages to be erased and making deleted data unrecoverable far faster and more thoroughly than on an HDD. Option C is correct because wear leveling relocates data across NAND blocks to spread erase cycles, so logical-to-physical mapping changes constantly and forensic tools cannot rely on fixed physical locations the way they can with HDD platters.

Option D is not correct because platter rotation and magnetic remanence are characteristics of HDDs, not SSD-specific challenges. Option E is not correct because controller-based compression is not a defining SSD forensic challenge in the way garbage collection, TRIM, and wear leveling are, and it is not marked as a correct answer here.

Exam trap

EC-CHFI often tests the distinction between HDD-specific features (like platter rotation and magnetic remanence) and SSD-specific challenges, so candidates mistakenly select HDD-related options because they sound technical, but they do not apply to solid-state drives.

47
MCQmedium

A security analyst is investigating a compromised Windows system and wants to see which processes were running at the time of memory capture. Which Volatility command should they use?

A.volatility -f mem.dump pslist
B.volatility -f mem.dump hashdump
C.volatility -f mem.dump malfind
D.volatility -f mem.dump netscan
AnswerA

The `pslist` plugin walks the doubly linked list of EPROCESS structures in the memory image, enumerating every running process at the time of capture. This directly satisfies the task of listing processes active on the compromised Windows system, making it the correct command. Note that because it relies on the linked list, processes that have deliberately unlinked themselves to evade detection will not appear, but for standard process enumeration it is the foundational Volatility command.

Why this answer

The `pslist` plugin in Volatility enumerates processes from the Windows kernel's EPROCESS structure list, showing all active processes at the time of memory capture. This is the correct command to identify running processes from a memory dump, as it directly parses the doubly-linked list of process objects maintained by the kernel.

Exam trap

CHFI often tests the distinction between `pslist` (which uses the kernel's process list) and `psscan` (which uses pool tag scanning), leading candidates to confuse `pslist` with other plugins like `malfind` or `netscan` that serve different forensic purposes.

How to eliminate wrong answers

Option B is wrong because `hashdump` extracts password hashes from the SAM registry hive, not running processes. Option C is wrong because `malfind` detects injected code or hidden processes by scanning for executable memory regions with suspicious permissions, but it does not list all running processes. Option D is wrong because `netscan` enumerates network connections and sockets, not processes.

48
Multi-Selectmedium

Which THREE of the following are characteristics of the Master File Table ($MFT) in NTFS? (Choose three.)

Select 3 answers
A.It contains a record for every file and directory on the volume
B.Small files can be stored resident within the $MFT record
C.Each record is typically 1024 bytes in size
D.It is located at a fixed position at the beginning of the volume
E.It is only used for directory metadata
AnswersA, B, C

The $MFT is the NTFS master file table, a structured sequence of file record segments acting as the volume's inventory. Every file and directory, including system files and the $MFT itself, occupies at least one record. Each record stores the file's attributes (name, timestamps, data stream pointers, security descriptors) via attribute headers, and the record's number is the low 48 bits of a file's reference, making the table the definitive catalog of all volume items.

Why this answer

Option A is correct because the $MFT in NTFS maintains at least one file record for every file and directory stored on the volume, serving as the central index of all objects. Option B is correct because NTFS supports resident data, meaning small files (and small attributes) can be stored directly inside the $MFT file record rather than in separate clusters, which improves access efficiency. Option C is correct because each $MFT file record is normally 1024 bytes in size, a standard NTFS structure size that holds the record header and its attributes.

Option D is incorrect because the $MFT is not guaranteed to sit at a fixed position at the start of the volume; its location is recorded in the boot sector, and it can be moved or fragmented. Option E is incorrect because the $MFT is not limited to directory metadata; it indexes all files and directories and stores their attributes and, when resident, their data.

Exam trap

The CHFI exam often tests the misconception that the $MFT is at a fixed physical location on the disk, but in reality its location is dynamic and stored in the boot sector, and candidates may also mistakenly think the $MFT only holds directory metadata rather than records for every file and directory.

49
MCQeasy

Which tool is specifically designed to acquire RAM from a Linux system for forensic analysis?

A.WinPmem
B.LiME
C.EnCase
D.FTK Imager
AnswerB

LiME (Linux Memory Extractor) is a loadable kernel module (LKM) designed specifically to acquire physical memory from Linux systems. By executing in kernel space, LiME can directly address physical memory pages and write them to a block device or transmit them over the network, overcoming the restrictions imposed on /dev/mem and /dev/kmem. It is the standard tool for forensically sound Linux RAM acquisition because it is kernel-version-specific and can be loaded on a live target without rebooting, making it the correct answer for this question.

Why this answer

LiME (Linux Memory Extractor) is a Loadable Kernel Module (LKM) specifically designed to capture volatile memory (RAM) from Linux systems. Unlike other tools that rely on user-space access, LiME operates at the kernel level, ensuring a more complete and forensically sound acquisition of the entire physical address space, including memory regions that user-space tools cannot reach.

Exam trap

The CHFI exam often tests the distinction between cross-platform tools and OS-specific tools, leading candidates to mistakenly choose a familiar Windows tool (like FTK Imager or WinPmem) for a Linux-specific task.

How to eliminate wrong answers

Option A (WinPmem) is wrong because it is a Windows-only memory acquisition tool, part of the Rekall project, and does not support Linux systems. Option C (EnCase) is wrong because it is a commercial forensic suite primarily used for disk imaging and analysis, not a dedicated tool for live RAM acquisition from Linux. Option D (FTK Imager) is wrong because it is a Windows-based forensic imaging tool that can acquire memory on Windows systems but lacks native support for Linux memory acquisition.

50
MCQmedium

During a forensic investigation, an analyst discovers data hidden in the Host Protected Area (HPA) of a hard drive. Which tool is commonly used to view and access the HPA?

A.PhotoRec
B.fdisk
C.dd
D.hdparm
AnswerD

hdparm issues ATA commands that read the drive's maximum addressable sector count and can unlock or reveal the Host Protected Area, which the BIOS and OS normally hide. It is the standard Linux utility for inspecting and accessing HPA regions during forensic examination.

Why this answer

D (hdparm) is correct because the Host Protected Area (HPA) is a reserved area on an ATA/IDE hard drive that can be accessed and manipulated using ATA commands. The hdparm utility in Linux provides the -N flag to view and change the HPA size, allowing an analyst to detect and access hidden data stored in this region.

Exam trap

The EC-CHFI exam often tests the misconception that dd can directly access the HPA, but dd only reads the logical block addresses visible to the OS, which excludes the HPA until it is explicitly revealed with hdparm.

How to eliminate wrong answers

Option A is wrong because PhotoRec is a file carving tool designed to recover deleted files from raw disk images or partitions; it does not interact with ATA commands or the HPA. Option B is wrong because fdisk is a partition table editor that works with the Master Boot Record (MBR) or GPT, but it cannot see or access the HPA since the HPA exists outside the addressable space reported by the drive. Option C is wrong because dd is a low-level data duplication tool that copies data from a source to a destination; while it can read a disk, it cannot directly access the HPA unless the HPA has been temporarily removed (e.g., with hdparm) because the HPA is hidden from standard read commands.

51
Multi-Selectmedium

Which TWO of the following are methods used to hide data within the NTFS file system?

Select 2 answers
A.USN Journal
B.File slack space
C.Volume Shadow Copy
D.Alternate Data Streams (ADS)
E.Encrypting File System (EFS)
AnswersB, D

File slack space is the gap between the end of a file's logical data and the end of the last allocated cluster in NTFS. This residual space can be filled with arbitrary data without affecting the file's size or visible content, making it invisible in normal directory listings. Since the operating system typically does not overwrite slack space until the cluster is reused, it provides a persistent and covert storage area. This is a classic steganographic method that forensic analysts detect by performing raw sector-level analysis of allocated clusters.

Why this answer

File slack space (B) is correct because NTFS allocates disk space in clusters (typically 4 KB), so a file smaller than its last cluster leaves unused bytes between the logical end-of-file and the end of the allocated cluster; this residual space can be written with hidden data without altering the file's visible content. Alternate Data Streams (ADS) (D) are correct because NTFS supports multiple named data streams per file via the $DATA attribute, allowing extra data to be attached to a file (e.g., 'file.txt:hidden.txt') that standard directory listings and many tools do not display. The USN Journal (A) is a change-logging metadata feature that records file system modifications, not a concealment method.

Volume Shadow Copy (C) creates point-in-time snapshots for backup/recovery, and EFS (E) provides encryption for confidentiality, neither of which is a technique for hiding data inside NTFS structures.

Exam trap

The CHFI exam often tests the distinction between hiding data (e.g., slack space, ADS) and protecting data (e.g., EFS) or system artifacts (e.g., USN Journal, Volume Shadow Copy), so candidates may confuse backup or encryption mechanisms with actual data hiding techniques.

52
MCQeasy

An investigator needs to recover deleted files from a USB drive formatted with FAT32. Which of the following techniques would be most effective, assuming the files have not been overwritten?

A.Check the journal for recent changes
B.Examine the FAT for unallocated clusters and reconstruct files
C.Analyze the $MFT for orphaned entries
D.Use the 'foremost' tool to carve based on file signatures
AnswerB

Correct. FAT32's File Allocation Table stores cluster chains. Deleted files have their FAT entries zeroed but data clusters remain. Examining the FAT for unallocated clusters and reconstructing from the directory entry's starting cluster and size allows recovery if not overwritten.

Why this answer

FAT32 does not have a journal (eliminating A). The Master File Table ($MFT) is used by NTFS, not FAT32 (eliminating C). While file carving with tools like 'foremost' (D) can recover files based on signatures, it is less effective for deleted files on FAT32 because it may fail to recover fragmented files and does not leverage the file system's own structure.

The most effective technique is to examine the File Allocation Table (FAT) for unallocated clusters and reconstruct the files from the directory entry's starting cluster and size (B), assuming the clusters have not been overwritten. This uses the file system metadata to directly locate the file's data.

Exam trap

A common trap is to assume that file carving (D) is always the best method. However, when the file system is intact and the metadata is available, analyzing the FAT provides a more reliable and efficient recovery. Also, note that FAT32 lacks a journal (A) and does not use $MFT (C).

How to eliminate wrong answers

Option A is wrong because FAT32 does not have a journal; journaling is a feature of NTFS (via $LogFile) and ext3/4, not FAT32. Option C is wrong because the $MFT (Master File Table) is a component of NTFS, not FAT32; FAT32 uses directory entries and the FAT, not an MFT. Option D is wrong because while 'foremost' is a valid file carving tool that works on any file system by searching for file signatures (headers/footers), it is a generic data carving technique that does not leverage the file system's metadata (like the FAT) to reconstruct files; it is less reliable for fragmented files and does not use the FAT's cluster chain information, making it less effective than option B for FAT32 recovery.

53
MCQeasy

A forensic analyst needs to acquire RAM from a live Linux system for memory analysis. Which tool is specifically designed for this purpose and can capture memory without rebooting?

A.FTK Imager
B.Volatility
C.LiME
D.dd
AnswerC

LiME (Linux Memory Extractor) is a loadable kernel module (LKM) purpose-built for capturing volatile memory from live Linux systems. It uses kernel APIs to traverse physical memory ranges, handles memory holes properly, and can write to a raw or LiME-format image file on local storage or stream it over TCP to a forensic server. Because it runs in kernel mode, it provides a forensically sound and consistent snapshot, making it the de facto standard for Linux RAM acquisition.

Why this answer

LiME (Linux Memory Extractor) is specifically designed to capture volatile memory from live Linux systems without requiring a reboot. It loads a kernel module that safely dumps RAM contents to a file, preserving the memory image for forensic analysis. Unlike dd, LiME handles memory-mapped I/O and avoids corrupting the system state during acquisition.

Exam trap

EC-Council often tests the distinction between acquisition tools (like LiME) and analysis tools (like Volatility), trapping candidates who confuse the role of Volatility as a memory capture tool rather than a post-acquisition analysis framework.

How to eliminate wrong answers

Option A is wrong because FTK Imager is a Windows-based forensic imaging tool that does not natively support live Linux memory acquisition; it can acquire disk images but not RAM from a running Linux system. Option B is wrong because Volatility is a memory analysis framework used to examine memory dumps, not a tool for capturing memory; it requires an existing memory image as input. Option D is wrong because dd is a generic disk cloning tool that can read from /dev/mem or /dev/crash, but it is not designed for safe, live memory acquisition on modern Linux systems—it may cause system instability or incomplete captures due to kernel memory protections and lacks the ability to handle memory-mapped regions properly.

54
MCQhard

During a forensic examination of a solid-state drive (SSD), you notice that files deleted several months ago cannot be recovered using traditional file carving tools. Which SSD feature is MOST likely preventing recovery?

A.TRIM
B.Over-provisioning
C.Garbage Collection
D.Wear levelling
AnswerA

TRIM is an ATA command that explicitly informs the SSD controller of pages that are no longer in use, prompting the controller to erase those physical blocks either immediately or during idle time. Because the erasure is performed at the flash level, the actual data is removed or invalidated, preventing recovery via file carving. This makes TRIM the critical factor that distinguishes SSD forensic examinations from HDD ones, as deleted files become inaccessible to software-based recovery tools.

Why this answer

The TRIM command (ATA Data Set Management command) allows the operating system to inform the SSD which data blocks are no longer in use. When TRIM is enabled, the SSD's controller immediately erases those blocks internally, making the original file data unrecoverable by file carving tools because the physical NAND cells are zeroed or marked as invalid. For files deleted months ago, TRIM would have already been issued for those LBAs, so traditional carving that relies on residual data in unallocated space fails.

Exam trap

EC-Council often tests the distinction between TRIM (an OS-to-SSD command that explicitly tells the drive to erase unused blocks) and Garbage Collection (a firmware-level process that may or may not erase data without TRIM), leading candidates to incorrectly choose Garbage Collection because they confuse background maintenance with the specific command that prevents recovery.

How to eliminate wrong answers

Option B (Over-provisioning) is wrong because over-provisioning reserves extra NAND capacity for performance and wear levelling, but it does not actively erase user-deleted data; it only provides spare blocks for the controller. Option C (Garbage Collection) is wrong because garbage collection consolidates valid data and erases stale blocks in the background, but it is triggered by the SSD's firmware and typically occurs after TRIM has marked blocks as invalid; without TRIM, garbage collection may not immediately erase deleted files. Option D (Wear levelling) is wrong because wear levelling distributes write/erase cycles across all NAND blocks to prolong drive life, but it does not intentionally erase user data; it moves data around and may incidentally overwrite old blocks, but it is not the primary mechanism preventing recovery of long-deleted files.

55
MCQmedium

An analyst finds evidence that an attacker used steganography to hide data within image files on the suspect's computer. Which of the following tools is MOST appropriate for detecting steganography in these images?

A.Foremost
B.Autopsy
C.Stegdetect
D.Volatility
AnswerC

Stegdetect is a specialized static analysis tool that scans image files for signatures of common steganographic algorithms such as jsteg, outguess, and F5. It performs statistical tests and histogram analysis on JPEG coefficients to identify embedded payloads, making it the most direct and purpose-built choice for confirming steganographic content in a suspected image.

Why this answer

Stegdetect is specifically designed to detect steganographic content in images by analyzing statistical anomalies in pixel data, such as those introduced by LSB (Least Significant Bit) embedding. It can identify common steganography tools like JSteg, JPHide, and OutGuess, making it the most appropriate choice for this scenario.

Exam trap

EC-Council often tests the distinction between file recovery tools (like Foremost) and steganography detection tools, leading candidates to mistakenly choose Foremost because it is associated with 'hidden' data recovery.

How to eliminate wrong answers

Option A is wrong because Foremost is a file carving tool used to recover deleted files based on headers and footers, not for detecting hidden data within intact image files. Option B is wrong because Autopsy is a digital forensics platform that provides a GUI for analyzing disk images and file systems, but it does not include built-in steganography detection capabilities. Option D is wrong because Volatility is a memory forensics framework for analyzing RAM dumps, such as processes and network connections, and is not used for static file analysis or steganography detection.

56
MCQhard

An analyst retrieves a forensic image of a hard drive and discovers that the size reported by the operating system is smaller than the actual physical capacity. The extra space is not accessible through standard partition tools. This hidden area is MOST likely:

A.Device Configuration Overlay
B.Host Protected Area
C.Volume slack
D.RAM slack
AnswerB

Host Protected Area (HPA) is the correct answer because it is a hidden region created using the ATA Set Max Address command, which makes the operating system see a smaller disk than the physical platter actually contains. This area cannot be accessed through normal OS commands and is frequently used to conceal data for forensic analysis or other purposes. When an analyst observes that the OS-reported capacity is less than the physical drive size, the HPA is exactly the hidden area responsible for that discrepancy.

Why this answer

The Host Protected Area (HPA) is a region on a hard drive that is hidden from the operating system by using the ATA SET MAX ADDRESS command to reduce the reported capacity. This area is not accessible through standard partition tools because the OS sees only the reduced address space, making it ideal for storing forensic or diagnostic data. The analyst's observation of a smaller reported size than physical capacity directly matches HPA behavior.

Exam trap

EC-Council often tests the distinction between HPA and DCO, where candidates confuse the ATA commands (SET MAX ADDRESS vs. DEVICE CONFIGURATION) and incorrectly assume DCO is the primary hidden area when the symptom is a reduced OS-reported size.

How to eliminate wrong answers

Option A is wrong because a Device Configuration Overlay (DCO) is a separate hidden area created by the ATA DEVICE CONFIGURATION command that can be removed to reveal additional space, but it does not reduce the OS-reported size below physical capacity via a simple address limit like HPA. Option C is wrong because volume slack refers to unused space at the end of a partition that is still within the partition's logical boundaries and accessible via partition tools, not a hidden area beyond the OS-reported capacity. Option D is wrong because RAM slack is the unused space in the last sector of a file's allocated clusters that is filled with RAM contents, which is a file system concept unrelated to hard drive hidden areas.

57
MCQmedium

During a forensic examination, an analyst uses Autopsy to view the contents of the Recycle Bin on a Windows 10 system. However, some files that were deleted by the user do not appear in the Recycle Bin. What is the MOST likely reason?

A.The Recycle Bin stores only files smaller than 1 GB
B.The files were encrypted
C.The files were deleted using Shift+Delete
D.The Recycle Bin was emptied
AnswerC

Holding Shift while pressing Delete (or selecting 'permanently delete') instructs the NTFS driver to unlink the file immediately without creating the $I metadata and $R data entries in the $Recycle.Bin folder. This bypasses the normal two-step Recycle Bin process, marking the clusters as free and removing the directory entry, so the file never appears in the Recycle Bin. In forensic practice, this is the classic explanation for why deleted files cannot be located in the Recycle Bin.

Why this answer

When a user deletes a file using Shift+Delete, the file bypasses the Recycle Bin entirely and is permanently removed from the file system. Autopsy, as a forensic tool, reads the Recycle Bin’s metadata (e.g., the $I and $R files) to list its contents, so files deleted with Shift+Delete will not appear there because they were never placed in the Recycle Bin.

Exam trap

The trap here is that candidates often assume the Recycle Bin stores all deleted files, but the EC-Council CHFI exam tests the specific behavior that Shift+Delete bypasses the Recycle Bin entirely, and that emptying the Recycle Bin removes the files from view but does not explain their absence if they were never placed there.

How to eliminate wrong answers

Option A is wrong because the Recycle Bin does not have a fixed size limit of 1 GB; it can store files of any size up to the configured maximum size (typically 10% of the drive), and files larger than that threshold are handled by prompting the user to permanently delete them. Option B is wrong because encryption does not affect whether a file is sent to the Recycle Bin; encrypted files are still moved to the Recycle Bin when deleted normally, and the Recycle Bin stores the encrypted data as-is. Option D is wrong because if the Recycle Bin had been emptied, the $I and $R files would still exist in the Recycle Bin folder until overwritten, and Autopsy could potentially recover them; the question states the files 'do not appear,' implying they were never placed there, not that they were removed after being placed.

58
MCQmedium

During an investigation, an analyst recovers a file from unallocated space that contains fragments of a deleted document. The file size is 512 bytes, but the cluster size of the volume is 4096 bytes. What is the term for the unused bytes between the end of the file and the end of the last cluster?

A.Volume slack
B.Drive slack
C.File slack
D.RAM slack
AnswerC

File slack is the unused bytes from the logical end of a file to the end of the last cluster allocated to that file, and it is the correct location for recovered remnant data. It consists of RAM slack (up to the sector boundary) plus the remaining bytes in the trailing cluster, which are typically not zeroed by the filesystem. Because old data can persist there after a file is overwritten or deleted, forensic examiners regularly recover intact fragments from file slack.

Why this answer

File slack refers to the unused bytes between the end of a file and the end of the last cluster allocated to that file. In this scenario, the file is 512 bytes but resides in a 4096-byte cluster, leaving 3584 bytes of slack space. This area can contain remnants of previously deleted data or metadata, making it a critical forensic artifact.

Exam trap

EC-Council often tests the distinction between RAM slack and file slack, and the trap here is that candidates confuse 'file slack' with 'RAM slack' because both involve unused bytes, but file slack encompasses the entire cluster remainder, while RAM slack is only the sector-level portion.

How to eliminate wrong answers

Option A is wrong because volume slack is the unused space at the end of a volume or partition, not between the end of a file and its cluster boundary. Option B is wrong because drive slack is not a standard forensic term; it is often confused with volume slack or unallocated space on the entire drive. Option D is wrong because RAM slack specifically refers to the unused bytes between the end of a file and the end of the sector (typically 512 bytes) that are filled with RAM contents during a write operation, not the cluster-level slack described here.

59
MCQhard

An analyst is investigating a Linux server that suffered a data breach. The attacker deleted several log files. The analyst runs `debugfs /dev/sda1` and issues the command `lsdel`. What is the purpose of this command in the context of file recovery?

A.List inodes of deleted files that still have allocated blocks
B.Recover deleted files from the journal
C.List all deleted directory entries in the journal
D.Display the current superblock information
AnswerA

The `lsdel` command in debugfs scans the filesystem's inode table for inodes marked as deleted but still retaining allocated blocks, indicating their data blocks have not yet been freed. It outputs a list of such inode numbers, along with size and block counts, serving as recovery candidates. This is a listing operation only; actual recovery would require separate steps like `dump` or manual block reassembly.

Why this answer

The `lsdel` command in `debugfs` lists inodes of deleted files that still have allocated data blocks. This is critical in forensic analysis because even after a file is deleted, its inode and data blocks may remain intact until overwritten, allowing recovery of the file's contents.

Exam trap

The trap here is that candidates confuse `lsdel` with a recovery command, but it only lists recoverable inodes, not the actual file contents, and they may mistakenly think it interacts with the journal or superblock.

How to eliminate wrong answers

Option B is wrong because `lsdel` does not recover files from the journal; it only lists inodes of deleted files with allocated blocks, and recovery requires additional steps like `dump` or `cat`. Option C is wrong because `lsdel` does not list directory entries in the journal; it operates on the inode table, not the journal, and directory entries are handled by `ls -d` or `ls -i` in debugfs. Option D is wrong because `lsdel` does not display superblock information; that is done with the `stats` command in debugfs.

60
MCQhard

A forensic investigator analyzing a RAID 5 array of three disks notices that one disk has failed. Can the investigator still reconstruct the data?

A.Yes, using the parity information from the remaining disks
B.No, RAID 5 requires all disks to be present
C.Yes, but only if the failed disk is the parity disk
D.No, because RAID 5 does not support hot swapping
AnswerA

RAID 5 uses a distributed parity scheme in which data and parity are interleaved across every disk in the array. If any single disk fails, the missing data can be reconstructed on-the-fly by reading the corresponding data and parity stripes from the two surviving disks and performing an XOR calculation. In a three-disk RAID 5, two remaining disks always provide enough information to rebuild the lost stripe, allowing the array to continue operating in a degraded state until the failed disk is replaced.

Why this answer

RAID 5 uses distributed parity across all disks in the array. When one disk fails, the data can be reconstructed by XORing the data and parity from the remaining disks. Since the parity is spread across all disks (not a dedicated parity disk), the investigator can rebuild the missing data as long as the remaining disks are functional.

Exam trap

The trap here is that candidates often confuse RAID 5 with RAID 4 (which uses a dedicated parity disk) or incorrectly assume that all disks must be present for data access, when in fact RAID 5 is fault-tolerant to a single disk failure.

How to eliminate wrong answers

Option B is wrong because RAID 5 is specifically designed to tolerate a single disk failure; it does not require all disks to be present for data reconstruction. Option C is wrong because RAID 5 does not have a dedicated parity disk; parity is distributed across all disks, so the failure of any single disk is recoverable regardless of which disk fails. Option D is wrong because hot swapping is a hardware feature unrelated to the ability to reconstruct data; RAID 5 supports reconstruction even without hot swapping, as long as the array is not degraded further.

61
MCQmedium

During a forensic acquisition of a suspect's SSD, the analyst notices that the drive supports TRIM. Which of the following is the most important consideration when acquiring the drive to preserve deleted data?

A.Perform a full format of the SSD before acquisition to clear any TRIM-related issues
B.Use a hardware write-blocker and acquire the drive immediately to minimize TRIM interference
C.Enable TRIM in the forensic tool to ensure the drive is optimized before imaging
D.The SSD should be powered on for several hours to allow TRIM to complete before imaging
AnswerB

Using a hardware write-blocker and acquiring the drive immediately is the only correct approach because the write-blocker physically prevents any host-initiated T commands, including TRIM, from reaching the SSD, preserving the current state. The urgency minimizes the opportunity for the SSD's internal garbage collection to run during idle time, which could erase blocks that still contain recoverable data. A forensic image captures both allocated and unallocated space, and acquiring without delay ensures maximum data retention before the controller reclaims any stale blocks.

Why this answer

SSDs with TRIM support automatically issue commands to erase deallocated blocks, making deleted data unrecoverable. Using a hardware write-blocker and acquiring the drive immediately minimizes the time the drive is powered on, reducing the chance that the operating system or the SSD's garbage collection will issue TRIM commands that permanently wipe deleted data.

Exam trap

EC-CHFI often tests the misconception that TRIM is beneficial for forensics or that formatting helps, when in fact TRIM is destructive to deleted data and must be prevented by immediate acquisition with a write-blocker.

How to eliminate wrong answers

Option A is wrong because performing a full format writes zeros or other patterns to all sectors, which would destroy any residual deleted data, making forensic recovery impossible. Option C is wrong because enabling TRIM in the forensic tool would actively instruct the SSD to erase deallocated blocks, which is the opposite of preservation — the goal is to prevent TRIM from running. Option D is wrong because powering on the SSD for several hours allows the drive's garbage collection and TRIM processes to run, which would erase deleted data blocks, making recovery impossible.

62
MCQeasy

During a forensic analysis of an NTFS volume, an investigator finds a file that appears to be hidden. Which NTFS feature allows data to be stored in a file without affecting the file's visible size in the directory listing?

A.Alternate Data Streams (ADS)
B.Volume Shadow Copy
C.USN Journal
D.Master File Table ($MFT)
AnswerA

Alternate Data Streams (ADS) are a legitimate NTFS feature that allow additional named data streams to be attached to a file, accessible via the syntax file.txt:stream. Because standard directory listings and file properties typically report only the primary unnamed stream, an investigator using conventional utilities may completely miss malicious payloads hidden in ADS. Forensic examiners must explicitly enumerate streams using specialized tools (e.g., streams.exe, lads, or forensic suites) and inspect the $MFT attribute list to identify these hidden data regions, as they are a classic anti-forensic hiding technique.

Why this answer

Alternate Data Streams (ADS) allow additional data to be attached to a file on an NTFS volume without altering the file's main data stream or its visible size in directory listings. This is possible because NTFS organizes file data into multiple streams; the default $DATA stream holds the visible content, while additional named streams can store hidden data. Tools like `dir` or Windows Explorer only report the size of the unnamed $DATA stream, making ADS an effective method for concealing data.

Exam trap

The CHFI exam often tests the misconception that the Master File Table ($MFT) is the primary location for hiding data, but the trap here is that ADS directly allows data to be stored in a file without changing its visible size, while $MFT manipulation (e.g., slack space) is a different, more complex technique.

How to eliminate wrong answers

Option B (Volume Shadow Copy) is wrong because it is a backup and recovery feature that creates point-in-time snapshots of volumes, not a mechanism for hiding data within a file without affecting its visible size. Option C (USN Journal) is wrong because it is a change journal that records modifications to files on an NTFS volume, used for tracking changes, not for storing hidden data. Option D (Master File Table ($MFT)) is wrong because it is the central directory structure that stores metadata about every file and folder, but it does not allow data to be hidden within a file without affecting its visible size; the $MFT itself can be a target for hiding data via techniques like slack space, but that is not the feature described.

63
MCQmedium

An analyst runs 'foremost -i disk.dd -o output' and recovers several JPEG files. However, some files are corrupted or incomplete. What is the most likely cause?

A.The files were fragmented across the disk, and foremost did not reassemble fragments
B.The files were stored in a journaling file system that overwrites deleted data quickly
C.The output directory had insufficient space to store the recovered files
D.The disk image contains bad sectors that could not be read
AnswerA

Foremost performs file carving by scanning for known header and footer signatures, assuming each file occupies a contiguous sequence of clusters on the raw image. If the target file is fragmented, the recovered output will consist of the first contiguous fragment up to the first footer (or the configured maximum file size), and subsequent fragments are ignored rather than reassembled. This yields truncated or corrupted files exactly matching the analyst's observation, because the tool never attempts to map logical file offsets across non-contiguous disk sectors.

Why this answer

Foremost is a file carving tool that relies on file headers and footers to recover data. It does not handle fragmentation; if a JPEG file's data blocks are non-contiguous on the disk, Foremost will only recover the first fragment up to the point where the next fragment begins, resulting in a corrupted or incomplete file. This is a known limitation of header/footer carving without fragmentation support.

Exam trap

CHFI often tests the misconception that file carving tools automatically handle fragmentation, leading candidates to overlook the fundamental limitation of header/footer carving without reassembly logic.

How to eliminate wrong answers

Option B is wrong because journaling file systems (e.g., NTFS, ext3/4) primarily protect metadata integrity and can overwrite deleted data, but Foremost carves raw data from the disk image regardless of file system structure; journaling does not inherently cause fragmentation or incomplete carving. Option C is wrong because insufficient output directory space would cause a write failure or error message, not the recovery of corrupted or incomplete files; Foremost would typically stop or warn, not produce partial files. Option D is wrong because bad sectors would cause read errors during imaging, not during carving from a completed disk image; if the image already contains unreadable sectors, those sectors would appear as zeros or errors, but Foremost would still recover complete files from readable sectors—corruption from bad sectors would be random, not specifically fragmentation-related.

64
MCQeasy

Which file system journal is commonly used in Linux ext3/ext4 to record metadata changes before they are committed to the main file system?

A.$LogFile
B.Journal (JBD/JBD2)
C.Recycle Bin
D.USN Journal
AnswerB

JBD/JBD2 is the journaling layer embedded in ext3 and ext4, recording metadata transactions in a circular log before committing them to the main file system. This satisfies the stem's requirement for a Linux journal that captures metadata changes pre-commit, enabling fast crash recovery and consistency checks.

Why this answer

The ext3 and ext4 file systems in Linux use the Journal (JBD/JBD2) layer to record metadata changes in a circular log before they are committed to the main file system. This journaling mechanism ensures file system consistency after a crash by allowing replay of committed transactions, with JBD2 specifically supporting ext4's 64-bit features and checksums.

Exam trap

The EC-Council CHFI exam often tests the confusion between Windows-specific artifacts (like $LogFile or USN Journal) and Linux journaling mechanisms, expecting candidates to recognize that ext3/ext4 rely on JBD/JBD2 rather than NTFS structures.

How to eliminate wrong answers

Option A is wrong because $LogFile is the journal file used by NTFS (New Technology File System) in Windows, not by Linux ext3/ext4. Option C is wrong because the Recycle Bin is a Windows feature for temporarily storing deleted files, not a journaling mechanism. Option D is wrong because USN Journal (Update Sequence Number Journal) is an NTFS feature in Windows that tracks changes to files and directories for indexing and backup, not a metadata journal for Linux file systems.

65
Multi-Selectmedium

Which TWO tools are specifically designed for file carving (recovering files based on signatures) and are commonly used in digital forensics?

Select 2 answers
A.Volatility
B.Scalpel
C.Foremost
D.EnCase
E.Autopsy
AnswersB, C

Scalpel is a dedicated file carving tool written in C, originally derived from Foremost but completely rewritten for speed and efficiency. It uses a configuration file (carve.conf) to define binary header and footer signatures, then scans raw byte streams to extract files without needing filesystem metadata. Its entire purpose is file carving, making it a correct answer.

Why this answer

Scalpel (B) is correct because it is a signature-based file carving tool derived from Foremost that reads a configurable header/footer database to extract files from raw disk images or unallocated space without relying on filesystem metadata. Foremost (C) is correct because it was originally developed for the U.S. Air Force OSI and carves files by matching file headers and footers (e.g., JPEG, PDF, ZIP) in disk images, making it a canonical carving utility in digital forensics.

Volatility (A) is a memory forensics framework for analyzing RAM dumps, not a file carver. EnCase (D) is a full commercial forensic suite that can recover files via filesystem parsing and some carving, but it is not specifically designed as a signature-based carving tool. Autopsy (E) is a graphical forensic platform that integrates carving modules (often via Scalpel or its own ingest modules) but is not itself a dedicated carving tool.

Exam trap

EC-Council often tests the distinction between dedicated file carving tools (Scalpel, Foremost) and broader forensic suites (EnCase, Autopsy) that include carving as a secondary feature, leading candidates to incorrectly select the more well-known commercial tools.

66
Multi-Selecthard

During a forensic analysis of an SSD, the analyst encounters challenges due to TRIM and wear-leveling. Which TWO statements accurately describe the impact of these features on data recovery?

Select 2 answers
A.TRIM immediately and permanently erases deleted file data at the block level
B.Wear-leveling can scatter fragments of a file across different NAND chips, complicating physical imaging
C.Both TRIM and wear-leveling are transparent to the operating system and have no impact on forensic analysis
D.Wear-leveling ensures that deleted files are overwritten with zeros to prevent forensic recovery
E.TRIM is only effective on HDDs, not SSDs
AnswersA, B

TRIM commands cause the SSD to erase blocks, preventing recovery.

Why this answer

A is correct because TRIM commands (ATA Data Set Management command) instruct the SSD controller to immediately erase invalidated logical block addresses (LBAs) at the block level, making the original data unrecoverable via standard forensic tools. This is not a simple deletion of file system metadata but a physical erasure of the underlying NAND flash cells, which prevents recovery of the file content even with advanced carving techniques.

Exam trap

EC-Council's CHFI exam often tests the misconception that TRIM is a file system operation or that wear-leveling actively sanitizes deleted data, when in reality TRIM is a hardware-level command and wear-leveling is a longevity mechanism that incidentally complicates forensic reconstruction.

67
MCQeasy

Which file system artifact in NTFS is used to hide data by appending a stream to an existing file without affecting its primary data stream?

A.USN Journal
B.$Recycle.bin
C.Alternate Data Streams (ADS)
D.Master File Table ($MFT)
AnswerC

Alternate Data Streams (ADS) is an NTFS feature that allows a single file to contain multiple data streams, so additional data can be attached to a file without altering its primary content or visibly increasing its size. An attacker can hide data by writing to a stream such as 'legit.exe:hidden.exe', and this data is not shown in standard directory listings or Explorer's size calculations. This makes ADS the classic NTFS data-hiding technique, and forensic examiners must explicitly enumerate streams to detect such hidden payloads.

Why this answer

Alternate Data Streams (ADS) are a feature of the NTFS file system that allows a file to have multiple data streams associated with it. Data written to an alternate stream does not appear in the primary stream, so the file's size and content as seen by standard tools remain unchanged, making it a common method for hiding data.

Exam trap

CHFI often tests the misconception that the $MFT itself is used to hide data, but the $MFT is a metadata structure, not a storage mechanism for appending hidden streams to files.

How to eliminate wrong answers

Option A is wrong because the USN Journal (Update Sequence Number Journal) is a change journal that records modifications to files and volumes, not a mechanism for hiding data within a file. Option B is wrong because $Recycle.bin is a system folder used to store deleted files before permanent removal, not a file system artifact for appending hidden streams. Option D is wrong because the Master File Table ($MFT) is the central directory of all files and folders on an NTFS volume, containing metadata and file records, but it does not provide a way to append hidden data streams to an existing file.

68
MCQmedium

During a forensic investigation, you need to acquire the RAM of a running Linux system. Which tool is specifically designed for memory acquisition on Linux?

A.Memdump
B.Volatility
C.WinPmem
D.LiME
AnswerD

LiME is a loadable kernel module built specifically for Linux memory acquisition, capturing RAM to a file or over the network with minimal footprint. Generic imaging tools copy disk, not volatile memory, so they cannot satisfy this requirement.

Why this answer

LiME (Linux Memory Extractor) is the correct tool because it is specifically designed to capture volatile memory (RAM) from Linux systems, loading as a loadable kernel module (LKM) to dump memory contents to a file or over the network. Unlike generic tools, LiME handles kernel address space layout randomization (KASLR) and can acquire memory without altering the system state, making it the standard for Linux forensic memory acquisition.

Exam trap

The CHFI exam often tests the distinction between acquisition and analysis tools, so the trap here is that candidates confuse Volatility (an analysis tool) with a memory acquisition tool, or assume WinPmem works on Linux because of the 'pmem' name, when it is Windows-only.

How to eliminate wrong answers

Option A is wrong because Memdump is a generic term for memory dumping utilities and not a specific tool for Linux memory acquisition; it often refers to Windows-based tools or simple dd commands, lacking the kernel module approach needed for reliable Linux RAM capture. Option B is wrong because Volatility is a memory analysis framework used to examine memory dumps, not a tool for acquiring memory; it processes existing dumps but does not perform the acquisition itself. Option C is wrong because WinPmem is a memory acquisition tool designed exclusively for Windows systems, using the winpmem driver to access physical memory, and is not compatible with Linux.

69
Multi-Selecthard

Which THREE of the following are characteristics of the GPT (GUID Partition Table) compared to MBR?

Select 3 answers
A.Partition information is stored in the boot code area
B.Uses a 32-bit Logical Block Address (LBA)
C.Partitions are identified by a Globally Unique Identifier (GUID)
D.Supports up to 128 primary partitions
E.Stores a backup partition table at the end of the disk
AnswersC, D, E

This is correct. Every GPT partition is assigned a Globally Unique Identifier (GUID) that serves as the partition's unique identity, in addition to a separate GUID for the partition type. These GUIDs are randomly generated and statistically unique, enabling robust identification that does not rely on disk order or numbering. The GPT header itself also has a GUID for the disk, making the entire layout disklabel-oriented rather than sector-offset-oriented.

Why this answer

Option C is correct because GPT identifies each partition and partition type with a Globally Unique Identifier (GUID), which avoids the MBR's reliance on simple numeric type bytes and enables robust, unique identification. Option D is correct because GPT by default provides space for 128 primary partitions in its partition entry array, unlike MBR's four-primary-partition limit. Option E is correct because GPT writes a primary partition table near the beginning of the disk and a backup copy at the end of the disk, allowing recovery if the primary table is damaged.

Option A is incorrect because GPT stores partition information in the GPT header and partition entry array, not in the boot code area; that description better fits MBR, where the partition table resides in the master boot record. Option B is incorrect because GPT uses 64-bit Logical Block Addressing (LBA), whereas MBR uses 32-bit LBA fields.

Exam trap

The CHFI exam often tests the misconception that GPT stores partition data in the boot code area (like MBR's partition table), but in reality, the boot code area in GPT is only a protective MBR with a single partition entry for backward compatibility.

70
MCQhard

During a forensic investigation of a Windows 10 system, you find that a suspect used the 'cipher /w:C:' command. What is the primary forensic implication of this action?

A.It encrypts all files on the C: drive
B.It wipes free space, hindering recovery of deleted files
C.It enables file system journaling
D.It removes alternate data streams from files
AnswerB

When you delete a file, its data blocks are merely marked as available, leaving the underlying bytes on the physical disk. The cipher /w command systematically overwrites these free-space regions with a sequence of patterns (e.g., 0x00, 0xFF, and random data) to ensure that remnants of deleted files are no longer recoverable through forensic tools. This process directly impedes recovery by destroying the residual data that would otherwise remain on the drive, which is why this is the correct description of the command's purpose.

Why this answer

The 'cipher /w:C:' command overwrites all free space on the C: drive with three passes of random data (0x00, 0xFF, and a random byte). This action permanently destroys the remnants of previously deleted files, making them unrecoverable by forensic tools. The primary forensic implication is that it severely hinders the recovery of deleted files, which is a common anti-forensic technique.

Exam trap

The trap here is that candidates confuse the 'cipher' command's encryption functionality (using /e) with its free-space wiping capability (using /w), leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because 'cipher /w' does not encrypt files; it only wipes free space, whereas encryption is performed by 'cipher /e' without the '/w' switch. Option C is wrong because the cipher command does not enable file system journaling; NTFS journaling is a built-in feature controlled by the 'fsutil' command, not by cipher. Option D is wrong because cipher /w does not specifically target alternate data streams (ADS); it wipes all free space indiscriminately, and ADS removal is typically done with tools like 'streams.exe' or by copying files to a non-NTFS volume.

71
MCQeasy

An analyst is investigating a compromised Linux system. Which file system structure holds metadata about every file and directory, including permissions, ownership, timestamps, and pointers to data blocks?

A.Journal
B.Block bitmap
C.Superblock
D.Inode
AnswerD

The inode is a per-file data structure containing all metadata for a file or directory, including mode/permissions, owner and group, size, access/modification/change timestamps, link count, and pointers to data blocks (direct, indirect, or extents). In ext4, the inode number, together with a generation counter, uniquely identifies a file, and directory entries map names to inode numbers. When a file is deleted, the inode may be cleared but often remains recoverable until the inode is reused, making it the central artifact for reconstructing file metadata and content.

Why this answer

The inode is the fundamental data structure in Unix/Linux file systems (e.g., ext2/3/4) that stores metadata for each file and directory, including permissions, ownership, timestamps (access, modify, change), and pointers to data blocks. Unlike the superblock or block bitmap, the inode does not store the file name (which is in directory entries) but contains all other essential metadata required for file system operations.

Exam trap

EC-Council often tests the misconception that the superblock holds per-file metadata, but the superblock only stores file system-wide configuration, not individual file attributes.

How to eliminate wrong answers

Option A is wrong because the journal is a circular log area used for crash recovery (e.g., in ext3/4) that records pending metadata or data changes, not a structure holding permanent metadata about every file. Option B is wrong because the block bitmap is a simple bit array that tracks which data blocks are free or allocated, not file-specific metadata like permissions or timestamps. Option C is wrong because the superblock stores global file system parameters (e.g., block size, total inode count, mount state) and does not contain per-file metadata.

72
MCQhard

An investigator is analyzing a RAID 5 array consisting of three disks. One disk fails and is replaced. After rebuilding, the file system appears corrupted. What is the MOST likely cause?

A.Two disks failed simultaneously
B.The replacement disk is smaller than the original
C.The file system is not supported by the RAID controller
D.The array was configured with an incorrect stripe size
AnswerB

RAID 5 requires all member disks to have identical usable capacity, and the controller maps data across disks based on that fixed geometry. If the replacement disk is physically or logically smaller than the original, the controller cannot reconstruct the missing disk's full block range, causing rebuild I/O errors that may corrupt the logical drive or abort the rebuild entirely. This is a classic cause of apparent data corruption after a disk replacement, because the array's own metadata and data layout become inconsistent with the replacement disk's reduced sector count.

Why this answer

In a RAID 5 array, all disks must have the same capacity for the array to function correctly. If a replacement disk is smaller than the original, the RAID controller will either refuse to rebuild or will rebuild using only the smaller disk's capacity, truncating data and causing file system corruption. This is a common cause of post-rebuild corruption because the parity and data stripes are misaligned or missing.

Exam trap

A common misconception is that any disk of the same interface type (e.g., SATA) can replace a failed disk in a RAID array, ignoring the critical requirement for identical or larger capacity.

How to eliminate wrong answers

Option A is wrong because if two disks failed simultaneously in a RAID 5 array, the array would be completely lost and unrecoverable, not merely corrupted after a rebuild. Option C is wrong because RAID controllers operate at the block level, not the file system level; file system support is irrelevant to the RAID controller's ability to rebuild. Option D is wrong because the stripe size is set during initial array creation and does not change during a rebuild; an incorrect stripe size would cause performance issues or incompatibility from the start, not corruption specifically after a disk replacement.

73
MCQmedium

In an ext4 file system, after a file is deleted, the inode's di_mode field is set to 0 and the block pointers are cleared. However, the file content may still be recoverable until what happens?

A.The data blocks are overwritten by new files
B.The file system is unmounted
C.The superblock is updated
D.The journal is committed
AnswerA

When a file is deleted in ext4, the inode is unlinked and its block pointers are cleared from the directory structure, but the physical blocks themselves are only marked as free in the block bitmap. They remain intact until a subsequent file allocation reuses those same blocks and overwrites them with new data. Once this happens, the original file content is irrecoverably lost unless remnants survive in unallocated slack space. Thus, overwriting by new files is the definitive event that destroys deleted file data.

Why this answer

When a file is deleted in ext4, the inode's di_mode is set to 0 and block pointers are cleared, but the actual data blocks on disk remain unchanged. The file content remains recoverable until those specific data blocks are overwritten by new file data, because only then is the original content physically destroyed. This is why data recovery tools can often restore deleted files if the blocks have not been reused.

Exam trap

The trap here is that candidates often confuse metadata operations (like journal commits or superblock updates) with actual data destruction, assuming that file system housekeeping erases content, when in reality only block overwrites remove the raw data.

How to eliminate wrong answers

Option B is wrong because unmounting the file system does not overwrite data blocks; it only flushes cached metadata and ensures a clean state, leaving the deleted file's data intact. Option C is wrong because updating the superblock (e.g., via tune2fs or after a fsck) modifies global file system metadata like block counts and mount state, not the individual data blocks of a deleted file. Option D is wrong because committing the journal finalizes metadata transactions (e.g., inode deletion) but does not touch the data blocks themselves; journal commits are about consistency, not data erasure.

74
MCQeasy

A forensic analyst is examining a FAT32 file system and finds that the file allocation table indicates a cluster chain ending with 0x0FFFFFFF. What does this value signify?

A.End-of-file marker
B.Free cluster
C.Reserved cluster
D.Bad cluster
AnswerA

In a FAT32 file system, each cluster is represented by a 32-bit entry in the File Allocation Table, and the value 0x0FFFFFFF (along with 0x0FFFFFF8–0x0FFFFFFF) marks the last cluster of a file's cluster chain. This end-of-cluster-chain marker tells the operating system that no further clusters follow, so the file's data ends at that cluster. It is not a byte offset or a physical sector location, but a logical FAT entry indicating chain termination.

Why this answer

In FAT32 file systems, the File Allocation Table (FAT) uses 32-bit entries to track cluster allocation. The value 0x0FFFFFFF is the defined end-of-file (EOF) marker, indicating that the current cluster is the last in a file's cluster chain. This is a standard FAT32 convention, distinct from other special values like free or bad clusters.

Exam trap

The trap here is confusing the FAT32 EOF marker (0x0FFFFFFF) with the bad cluster marker (0x0FFFFFF7) or the reserved cluster range (0x0FFFFFF0–0x0FFFFFF6), as EC-Council often tests the exact hex values to catch candidates who memorize concepts without the precise numbers.

How to eliminate wrong answers

Option B is wrong because a free cluster is represented by the value 0x00000000 in FAT32, not 0x0FFFFFFF. Option C is wrong because reserved clusters are indicated by values in the range 0x0FFFFFF0 through 0x0FFFFFF6, not 0x0FFFFFFF. Option D is wrong because a bad cluster is marked with the value 0x0FFFFFF7 in FAT32, which is a specific sentinel for physical media defects.

75
MCQhard

During a forensic examination of a solid-state drive (SSD), the analyst notices that the TRIM command was enabled. What challenge does this pose for data recovery?

A.It erases data blocks immediately after deletion, preventing recovery
B.It causes fragmentation, making file recovery more complex
C.It causes the drive to encrypt data automatically
D.It physically destroys the NAND cells, making the drive unusable
AnswerA

When the OS deletes a file on an SSD with TRIM enabled, it sends an ATA DATA SET MANAGEMENT command that instructs the controller to physically erase the involved NAND blocks right away, rather than simply marking the space as reusable in the file system. This immediate erasure means that the actual data cells are zeroed or invalidated, eliminating the possibility of recovery with conventional file carving or deep recovery tools, which rely on residual data. From a forensic perspective, TRIM effectively defeats many standard deleted-file recovery workflows on modern SSDs.

Why this answer

The TRIM command (ATA Data Set Management command) instructs the SSD controller to immediately erase the physical NAND blocks corresponding to deleted logical block addresses (LBAs). This proactive garbage collection operation resets the cells to an erased state, making it impossible for forensic tools to recover the original data from those blocks, as the data is physically overwritten with null values or marked as invalid.

Exam trap

The trap here is that candidates may confuse TRIM with wear leveling or assume it only affects performance, missing the critical forensic implication that TRIM permanently destroys deleted data at the physical NAND level, making recovery impossible even with advanced techniques like chip-off or JTAG.

How to eliminate wrong answers

Option B is wrong because TRIM does not cause fragmentation; in fact, TRIM helps maintain performance by allowing the SSD controller to optimize block allocation, reducing write amplification and fragmentation. Option C is wrong because TRIM is a command for block erasure, not encryption; SSDs may support hardware encryption (e.g., OPAL or eDrive), but TRIM itself does not encrypt data. Option D is wrong because TRIM does not physically destroy NAND cells; it simply marks blocks as invalid for garbage collection, and normal wear from program/erase cycles is what eventually degrades cells, not the TRIM command itself.

Page 1 of 2 · 139 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Chfi Storage Filesystem questions.