CHFI Storage Forensics and File System Analysis Practice Question
Which TWO of the following are challenges specific to SSD forensics compared to HDD forensics?
⚠ Common exam trap
CHFI often tests the distinction between challenges that are universal to all storage forensics versus those that are unique to SSD technology, so candidates mistakenly select options like 'file system metadata overwritten' or 'slack space' which are common to both HDDs and SSDs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wear leveling distributes writes, complicating data location
Option A is correct because SSD controllers use wear leveling to spread writes across flash blocks, so logical block addresses no longer map predictably to physical NAND locations, making it hard to determine where data actually resides. Option E is correct because the ATA TRIM command (and SCSI UNMAP) tells the SSD controller that deleted blocks are no longer needed, allowing them to be erased during garbage collection, which can destroy evidence that would persist on an HDD. Option B is not SSD-specific, since file system metadata can be overwritten on any storage medium. Option C is incorrect because magnetic remanence is a property of magnetic HDD platters, not SSDs. Option D is not SSD-specific either, as slack space remnants of deleted files exist in file systems on both HDDs and SSDs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Wear leveling distributes writes, complicating data location
Why this is correct
Wear leveling is inherent to NAND flash: because each block can endure only a limited number of program/erase cycles, the SSD controller continually remaps logical block addresses to different physical NAND cells and performs garbage collection. This dynamic mapping means a file's data is scattered and relocated over time, so traditional HDD-style forensic analysis that expects fixed sectors or known physical locations cannot reliably locate the original data.
- ✗
File system metadata may be overwritten
Why it's wrong here
File system metadata can be overwritten on literally any rewritable storage device, including conventional magnetic hard drives, USB flash drives, and memory cards. Because this behavior is a property of the file system and write path rather than of NAND flash technology, it is a generic forensic obstacle and not a challenge that is specific to solid-state drives.
- ✗
Magnetic remanence allows data recovery
Why it's wrong here
Magnetic remanence refers to the lingering magnetization left on ferromagnetic media after data is erased, and it is a characteristic of HDD platters, not SSDs. An SSD stores bits as trapped charge in floating-gate transistors, so there is no magnetic pattern to recover with techniques like magnetic force microscopy; this option describes an HDD-specific phenomenon.
- ✗
Slack space contains remnants of deleted files
Why it's wrong here
Slack space is the unused region between the end of a file's logical data and the end of its allocated cluster, created by filesystem block allocation. It exists on every filesystem regardless of underlying storage technology, so while it can contain remnants of previously larger files, it is not a forensic complication unique to SSDs and does not distinguish SSD forensics from HDD forensics.
- ✓
TRIM command erases deleted data
Why this is correct
The TRIM command is an ATA interface command that notifies the SSD which logical blocks are no longer in use, prompting the controller to erase or mark those NAND pages as invalid before future writes. This proactive physical erasure can permanently destroy deleted data in a way that ordinary overwriting on an HDD does not, making it a storage-technology-specific challenge that forensic investigators must account for on modern solid-state drives.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.