Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

Which forensic tool is specifically designed to recover lost partitions or file system structures and can also be used for data carving?

⚠ Common exam trap

The EC-CHFI exam often tests the distinction between tools designed for storage forensics (like TestDisk) versus memory forensics (like Volatility) or general forensic suites (like EnCase), leading candidates to choose a tool that is more well-known but not specialized for partition recovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TestDisk

TestDisk is specifically designed to recover lost partitions and repair file system structures, making it the correct choice for this scenario. It also includes data carving capabilities through its companion tool PhotoRec, allowing it to recover files from unallocated space or damaged volumes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sleuth Kit

    Why it's wrong here

    Sleuth Kit analyses existing file system images and recovers deleted files within an intact structure; it does not rebuild lost partitions, which is the scenario's requirement. It is tempting because it performs file system forensics, and would be correct for examining a mounted image's directory entries and metadata.

  • ✗

    EnCase

    Why it's wrong here

    EnCase acquires and analyses disk images and recovers deleted files, but partition table reconstruction and file system repair are not its designed function. It is tempting because it is a full forensic suite, and would be correct for imaging a suspect drive and examining artefacts within an intact file system.

  • ✓

    TestDisk

    Why this is correct

    TestDisk rebuilds damaged partition tables and lost file system structures, and its bundled PhotoRec component performs file carving from unallocated space. This satisfies the stem's dual requirement, whereas tools such as Autopsy or EnCase analyse acquired images rather than repairing partition structures.

  • ✗

    Volatility

    Why it's wrong here

    Volatility parses memory captures for running processes, network connections and injected code; it does not rebuild partition tables or file system structures, nor carve files from unallocated space. It is tempting because it is a forensic tool, and would be correct for live memory analysis of a compromised host.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.