CHFI Storage Forensics and File System Analysis Practice Question
Which TWO of the following are examples of file carving tools? (Select two.)
⚠ Common exam trap
The CHFI exam often tests the distinction between acquisition/imaging tools (like dd, FTK Imager, WinPmem) and file carving tools (like PhotoRec, Foremost), so candidates mistakenly select tools that create forensic images or capture memory instead of those that recover files from raw data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PhotoRec
PhotoRec (C) is a file-carving tool that recovers files by scanning raw disk or image data for known file signatures and reconstructing content without relying on filesystem metadata. Foremost (D) is likewise a signature-based carving utility originally developed for law enforcement that recovers files from disk images and unallocated space using header/footer patterns. WinPmem (A) is a memory acquisition tool, not a carving tool, so it does not belong. FTK Imager (B) is primarily a forensic imaging and preview tool rather than a file carver. dd (E) is a low-level bit-stream imaging/copying utility, not a carving tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WinPmem
Why it's wrong here
WinPmem is a memory acquisition tool that captures the contents of physical RAM into a raw image file for volatile memory analysis. It does not operate on disk images or raw block devices to recover files based on internal signatures, and therefore is not categorized as a file carving tool. Its purpose is preserving the state of running processes, network connections, and other ephemeral data.
- ✗
FTK Imager
Why it's wrong here
FTK Imager is primarily a forensic imaging and evidence preview tool that creates sector-by-sector copies of storage media and allows investigators to browse the contents of those images. While it has limited ability to recover deleted files via its 'Export Files' feature, it is not a dedicated signature-based carver that scans unallocated space using file headers and footers. The tool's core function is acquisition, not extraction of fragmented or unknown file types.
- ✓
PhotoRec
Why this is correct
PhotoRec is a legitimate file carving tool developed by Christophe Grenier as part of the TestDisk suite. It scans raw disk images or partitions by reading data block by block and matching known file signatures to reconstruct files independent of the filesystem metadata. It is especially effective for recovering photos and other multimedia from formatted or damaged media, making it a correct answer to the question.
- ✓
Foremost
Why this is correct
Foremost is a classic file carving utility originally created by the United States Air Force Office of Special Investigations, and is built around a configuration file of file header and footer signatures. It processes a raw input file such as a disk image and copies data between matched signatures to recover files, even if the original filesystem is absent or corrupted. This signature-based approach is a canonical example of file carving.
- ✗
dd
Why it's wrong here
dd is a low-level utility used to perform bitstream copies of disks, partitions, or files, often to create forensic images or convert data between formats. It does not inspect file content, identify file types, or extract files from unallocated space; it simply copies raw bytes from one location to another. Because it lacks any signature matching or reconstruction logic, it is not a file carving tool.
Go deeper
Related to this question
Learn chapter
Data Acquisition and Duplication Techniques
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.