CHFI Storage Forensics and File System Analysis Practice Question
Which forensic tool is specifically designed to recover lost partitions or file system structures and can also be used for data carving?
⚠ Common exam trap
The EC-CHFI exam often tests the distinction between tools designed for storage forensics (like TestDisk) versus memory forensics (like Volatility) or general forensic suites (like EnCase), leading candidates to choose a tool that is more well-known but not specialized for partition recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TestDisk
TestDisk is specifically designed to recover lost partitions and repair file system structures, making it the correct choice for this scenario. It also includes data carving capabilities through its companion tool PhotoRec, allowing it to recover files from unallocated space or damaged volumes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sleuth Kit
Why it's wrong here
Sleuth Kit analyses existing file system images and recovers deleted files within an intact structure; it does not rebuild lost partitions, which is the scenario's requirement. It is tempting because it performs file system forensics, and would be correct for examining a mounted image's directory entries and metadata.
- ✗
EnCase
Why it's wrong here
EnCase acquires and analyses disk images and recovers deleted files, but partition table reconstruction and file system repair are not its designed function. It is tempting because it is a full forensic suite, and would be correct for imaging a suspect drive and examining artefacts within an intact file system.
- ✓
TestDisk
Why this is correct
TestDisk rebuilds damaged partition tables and lost file system structures, and its bundled PhotoRec component performs file carving from unallocated space. This satisfies the stem's dual requirement, whereas tools such as Autopsy or EnCase analyse acquired images rather than repairing partition structures.
- ✗
Volatility
Why it's wrong here
Volatility parses memory captures for running processes, network connections and injected code; it does not rebuild partition tables or file system structures, nor carve files from unallocated space. It is tempting because it is a forensic tool, and would be correct for live memory analysis of a compromised host.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.