Courseiva

CHFI · topic practice

OS and File System Forensics practice questions

This domain covers forensic examination of Windows and Linux file systems: NTFS metadata (MFT, $LogFile, $UsnJrnl), FAT/exFAT structures, ext2/3/4 inodes and journaling, deleted-file recovery, timestamps, and evidence acquisition. Questions are scenario-based, asking you to interpret artifacts, choose sound acquisition methods, and explain what file-system records reveal about attacker or user activity.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
14 questionsDomain: OS and File System Forensics

What the exam tests

What to know about OS and File System Forensics

Be able to explain what NTFS and ext artifacts (MFT, inodes, journals, $UsnJrnl) reveal about file creation, deletion, and tampering, and to select a write-blocked, hashed acquisition method. The single most important thing: preserve evidence integrity while correctly interpreting file-system metadata.

NTFS artifacts: $MFT records, $LogFile, $UsnJrnl, $Bitmap, alternate data streams, and resident vs non-resident attributes

Linux ext inode fields, orphan inode handling, journal recovery, and interpreting syslog entries about deleted or unlinked files

Write-blocked, hash-verified forensic imaging (dd, FTK Imager, EnCase) preserving original evidence integrity

Deleted-file and slack-space recovery, plus MAC(b) timestamp interpretation and time-zone normalization across systems

Watch out for

Common OS and File System Forensics exam traps

  • ▸Assuming a deleted file is unrecoverable because the directory entry is gone; NTFS $MFT and ext inodes may still hold metadata and data runs.
  • ▸Imaging a live drive without a hardware or software write blocker, or skipping hash verification, which breaks evidence integrity and admissibility.
  • ▸Treating file MAC times as absolute truth; they can be altered by attackers, and time-zone or system-clock differences mislead timelines.

Practice set

OS and File System Forensics questions

14 questions · select your answer, then reveal the explanation

During a forensic investigation of a compromised Linux server, an investigator needs to recover deleted files from an ext4 filesystem. Which method should the investigator use to maximize recovery of file content, considering the filesystem may have been partially overwritten?

A forensic analyst is examining a Windows 10 system and needs to determine the last boot time of the system. Which registry hive and key should the analyst query to find this information?

Which TWO of the following are valid locations in a Windows system where forensic evidence of USB device connection can be found?

Drag and drop the steps to perform a forensic analysis of a Windows registry using RegRipper into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each forensic acquisition method to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Collecting data from a running system

Collecting data from powered-off media

Copying only active files and metadata

Bit-for-bit copy of entire storage device

Collecting only fragments of unallocated space

A forensic investigator is analyzing a Linux server running ext4 that was compromised. The investigator needs to recover a deleted file that contained sensitive data. The file was deleted just before the server was powered off. The investigator has created a forensic image of the disk and is now examining it. Which of the following techniques is most likely to successfully recover the deleted file?

A forensic analyst is examining a Windows 10 system and needs to determine the last time a specific user logged on. The analyst has access to the Windows registry. Which registry key should the analyst examine to find the last logon time for a local user account?

During a forensic investigation, an analyst needs to preserve the integrity of evidence on a hard drive. Which of the following is the best practice for acquiring an image of the drive?

You are a forensic investigator responding to a security incident at a medium-sized company. The incident involved an attacker gaining unauthorized access to a Windows Server 2019 system. The server was taken offline by the IT team immediately after detection. Your task is to acquire forensic evidence from the server's hard drive. The server has a single 500 GB NTFS partition. You have a forensic workstation with a write blocker, a SATA-to-USB adapter, and a forensic imaging tool that supports both dd and EWF (E01) formats. The server is still physically in the server room, and the IT team has powered it off. You need to create a forensic image that preserves the integrity of the evidence and allows for efficient analysis. Which of the following is the most appropriate course of action?

During a forensic investigation of a Windows 10 system, you need to analyze the file system to recover deleted files. Which TWO file system artifacts would be most useful for this purpose?

A forensic analyst is reviewing the syslog from a compromised Linux server. Based on the exhibit, what does the 'orphan inode deleted' message indicate?

Exhibit

Refer to the exhibit.

=== Linux log excerpt (var/log/syslog) ===
Jan 12 10:15:32 server1 kernel: [ 1234.5678] EXT4-fs (sda1): recovery complete
Jan 12 10:15:33 server1 kernel: [ 1234.5680] EXT4-fs (sda1): mounted filesystem with ordered data mode. Opts: (null)
Jan 12 10:15:34 server1 sshd[2345]: Accepted publickey for root from 192.168.1.10 port 54321 ssh2: RSA SHA256:abc...
Jan 12 10:15:35 server1 sshd[2346]: Received disconnect from 192.168.1.10 port 54321:11: disconnected by user
Jan 12 10:15:36 server1 kernel: [ 1234.5700] EXT4-fs (sda1): 1 orphan inode deleted
Jan 12 10:15:37 server1 kernel: [ 1234.5702] EXT4-fs (sda1): 1 orphan inode deleted

You are a forensic investigator responding to an incident on a Windows 10 workstation used by a finance manager. The user reports that a critical spreadsheet containing quarterly budget data was accidentally deleted from the Desktop yesterday at approximately 3:00 PM. The system has been used normally since then, and the user has not emptied the Recycle Bin. You have created a forensic image of the drive using FTK Imager. The Recycle Bin contains a file named 'Quarterly_Budget.xlsx', but it appears to be a shortcut (size 1 KB). The user insists the original file was several megabytes. You need to recover the original file. Which action should you take next?

A forensic investigator is examining a Windows 10 workstation that was seized after a suspected data exfiltration. The user claims they only used legitimate cloud storage. The investigator wants to determine which USB mass storage devices were previously connected to the system by examining the Windows registry. Which registry location should the investigator examine to find the device instance IDs and associated volume serial numbers of previously connected USB storage devices?

A forensic investigator is analyzing a Linux system that was compromised. The investigator needs to examine the file system for evidence of unauthorized access. The system uses the ext4 file system. Which TWO of the following file system artifacts can provide evidence of file creation, modification, or access times? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused OS and File System Forensics sessions

Start a OS and File System Forensics only practice session

Every question in these sessions is drawn from the OS and File System Forensics domain — nothing else.

Related practice questions

Related CHFI topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CHFI exam test about OS and File System Forensics?
Be able to explain what NTFS and ext artifacts (MFT, inodes, journals, $UsnJrnl) reveal about file creation, deletion, and tampering, and to select a write-blocked, hashed acquisition method. The single most important thing: preserve evidence integrity while correctly interpreting file-system metadata.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just OS and File System Forensics questions in a focused session?
Yes — the session launcher on this page draws every question from the OS and File System Forensics domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CHFI topics?
Use the topic links above to move to related areas, or go back to the CHFI question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CHFI exam covers. They are not copied from any real exam or dump site.