Courseiva

CHFI · topic practice

Storage Forensics and File System Analysis practice questions

This domain covers forensic acquisition and analysis of storage media and file systems, including SSD/HDD imaging, NTFS artifacts like $LogFile and $MFT, file carving, and steganography detection. Questions test tool selection, artifact interpretation, and handling challenges such as TRIM and deleted file recovery in CHFI scenarios.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Storage Forensics and File System Analysis

What the exam tests

What to know about Storage Forensics and File System Analysis

A candidate must select correct forensic tools for imaging, artifact analysis, carving, and steganography detection. The single most important thing is to understand NTFS artifacts and SSD limitations, especially TRIM effects on deleted file recovery.

NTFS $LogFile and $MFT record file creation, deletion, and modification events.

File carving tools like Foremost and Scalpel scan raw data for headers and footers.

Steganography detection using Stegdetect, StegExpose, or zsteg on image files.

SSD acquisition challenges: TRIM, wear leveling, and garbage collection after power-off.

Watch out for

Common Storage Forensics and File System Analysis exam traps

  • ▸Assuming deleted files are fully recoverable from SSDs; TRIM and garbage collection may have erased data blocks after 24 hours.
  • ▸Confusing $LogFile with $MFT; $LogFile records transactional changes while $MFT stores file metadata.
  • ▸Using file system–dependent recovery tools for carving; carving requires raw signature scanning, not directory parsing.

Practice set

Storage Forensics and File System Analysis questions

20 questions · select your answer, then reveal the explanation

An investigator uses FTK Imager to capture a forensic image of a suspect's hard drive. During acquisition, the tool reports that the DCO (Device Configuration Overlay) is present. What does this indicate?

Which THREE of the following are file systems that use journaling to maintain integrity?

During a forensic investigation, an analyst finds a file with a creation timestamp earlier than the volume's formatted timestamp. Which of the following is the most likely explanation?

In an ext3 file system, after deleting a file, the inode's link count drops to 0, but the data blocks remain. Which of the following is true regarding recovery?

An investigator uses the Volatility framework on a memory dump from a Windows 10 system. Which command would list all processes, including those hidden by rootkits?

A forensic investigator is examining a Mac system with APFS. Which artifact would be most useful for determining the exact time a file was moved to the Trash?

In a RAID 5 array with three disks, one disk fails. The investigator images the remaining two disks and wants to reconstruct the missing data. Which approach is most appropriate?

An investigator is analyzing a memory dump with Volatility and wants to identify network connections. Which TWO commands can provide information about TCP and UDP connections? (Select 2)

During an investigation, an analyst recovers deleted files from an NTFS volume. She notices that some files have data hidden in a stream that is not visible in regular directory listings. This stream is associated with a file but not stored in the $MFT. Which NTFS feature is being used to hide the data?

In FAT32, the File Allocation Table (FAT) is used to track which clusters are allocated to files. If a file is deleted, what happens to the FAT entries for that file?

During a forensic examination of an ext4 filesystem, the analyst discovers that a suspicious file was deleted but the inode still exists in the filesystem. Which of the following techniques would MOST likely recover the file's data?

Which TWO of the following are valid techniques for acquiring RAM in a Windows system?

During a forensic investigation, you find an NTFS volume with a file that has an alternate data stream (ADS). Which command in Windows can be used to list all ADS on a file?

An analyst is investigating a compromised Linux system and runs `ls -i` on a deleted file's directory. The inode number is 12345. Which tool can recover the file contents by referencing the inode?

In NTFS, the $MFT file contains metadata about every file and directory on the volume. When a file is deleted, its $MFT record is marked as free. What information in the $MFT record is MOST useful for recovering a deleted file?

During a forensic analysis of a compromised server, you discover that a rootkit has hidden itself by modifying the HPA (Host Protected Area) of the hard disk. Which tool can detect the presence of an HPA by comparing the reported size with the actual number of sectors?

Which TWO of the following are common challenges in SSD forensics that can hinder data recovery?

A forensic examiner acquires a RAM image from a Windows 10 system and uses Volatility to analyze it. Which command would list all running processes along with their parent process IDs and command lines?

During a forensic analysis of an APFS volume, the investigator needs to examine file metadata such as creation time, modification time, and extended attributes. Which APFS structure contains this information?

Which TWO of the following are valid methods to hide data on an NTFS volume? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Storage Forensics and File System Analysis sessions

Start a Storage Forensics and File System Analysis only practice session

Every question in these sessions is drawn from the Storage Forensics and File System Analysis domain — nothing else.

Related practice questions

Related CHFI topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CHFI exam test about Storage Forensics and File System Analysis?
A candidate must select correct forensic tools for imaging, artifact analysis, carving, and steganography detection. The single most important thing is to understand NTFS artifacts and SSD limitations, especially TRIM effects on deleted file recovery.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Storage Forensics and File System Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the Storage Forensics and File System Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CHFI topics?
Use the topic links above to move to related areas, or go back to the CHFI question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CHFI exam covers. They are not copied from any real exam or dump site.