CHFI Storage Forensics and File System Analysis Practice Question
Which three of the following are common techniques used to hide data on a storage device? (Choose THREE.)
⚠ Common exam trap
The CHFI exam often tests the distinction between legitimate storage management features (like journaling and TRIM) and actual data hiding techniques, leading candidates to confuse journaling or TRIM with covert storage methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Host Protected Area (HPA)
Host Protected Area (HPA) (B) is a hidden region of a hard disk defined by the ATA standard outside the addressable range reported to the OS, commonly used to conceal data from normal file access. Alternate Data Streams (ADS) in NTFS (C) allow additional data to be attached to a file without appearing in directory listings or standard file size, making them a classic hiding technique. Slack space (E), including file slack and volume slack, is leftover storage between the logical end of a file and the end of its allocated cluster or partition, and can be used to stash data invisible to normal file reads. File system journaling (A) is a reliability feature that logs metadata changes for crash recovery, not a concealment method, and the TRIM command (D) is an SSD maintenance operation that informs the drive which blocks are no longer in use, so neither hides data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
File system journaling
Why it's wrong here
File system journaling is a metadata consistency mechanism, not a data-hiding technique. It records pending changes in a log (e.g., ext3/4 journal or NTFS $LogFile) so that after a crash the filesystem can be replayed or rolled back to a consistent state. While journal entries can incidentally contain remnants of file activity, journaling itself provides no intentional way to conceal data from the operating system or forensic examiners.
- ✓
Host Protected Area (HPA)
Why this is correct
A Host Protected Area (HPA) is a reserved region on ATA/IDE hard disk drives that is set via the SET MAX ADDRESS ATA command. The standard OS and BIOS address space excludes this area, making it invisible to normal disk access and common forensic imaging tools, yet the data physically remains on the platters. Specialized forensic software or low-level ATA commands are required to detect, access, or image an HPA, which is why it is a recognized anti-forensic hiding location.
- ✓
Alternate Data Streams (ADS) in NTFS
Why this is correct
Alternate Data Streams (ADS) are a feature of the NTFS filesystem that allows multiple data streams to be associated with a single file entry. Clever users can attach hidden data to a legitimate file—such as typing `type hidden.txt > visible.txt:hidden.txt`—and the stream will not appear in standard directory listings or Explorer, remaining invisible to casual users and tools that do not enumerate streams. Forensic examiners must inspect the MFT or use specialized tools like `streams.exe` to reveal these hidden payloads.
- ✗
TRIM command
Why it's wrong here
The TRIM command is an ATA interface feature for solid-state drives (SSDs) that informs the drive which data blocks are no longer in use so they can be erased during garbage collection. This improves performance and wear leveling but does not create a hidden storage region; in fact, TRIM actively erases data remnants, which can hamper forensic recovery, but it is fundamentally a maintenance operation, not a technique for concealing data.
- ✓
Slack space (file slack, volume slack)
Why this is correct
Slack space refers to the unused bytes in a cluster after the end of a file's logical data (file slack) and the unused space at the end of a partition or volume (volume slack). Because the operating system does not overwrite this residual area during normal file writes, old data from previously deleted files can persist and be intentionally planted there to avoid detection. Forensic tools extract slack space to recover hidden or remnant data, making it a classic data-hiding location.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.