Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

Which TWO of the following are methods used to hide data within the NTFS file system?

⚠ Common exam trap

The CHFI exam often tests the distinction between hiding data (e.g., slack space, ADS) and protecting data (e.g., EFS) or system artifacts (e.g., USN Journal, Volume Shadow Copy), so candidates may confuse backup or encryption mechanisms with actual data hiding techniques.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

File slack space

File slack space (B) is correct because NTFS allocates disk space in clusters (typically 4 KB), so a file smaller than its last cluster leaves unused bytes between the logical end-of-file and the end of the allocated cluster; this residual space can be written with hidden data without altering the file's visible content. Alternate Data Streams (ADS) (D) are correct because NTFS supports multiple named data streams per file via the $DATA attribute, allowing extra data to be attached to a file (e.g., 'file.txt:hidden.txt') that standard directory listings and many tools do not display. The USN Journal (A) is a change-logging metadata feature that records file system modifications, not a concealment method. Volume Shadow Copy (C) creates point-in-time snapshots for backup/recovery, and EFS (E) provides encryption for confidentiality, neither of which is a technique for hiding data inside NTFS structures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    USN Journal

    Why it's wrong here

    The Update Sequence Number (USN) Journal is an NTFS change journal that records modifications to files and directories for indexing, backup, and recovery. It is specifically designed to log metadata changes, not to conceal data, and forensic examiners routinely parse it to reconstruct filesystem activity. Because it stores entries about every change, it is an invaluable investigative artifact rather than a data-hiding technique. Attempting to hide data in the journal would actually create more traces, undermining any concealment.

  • ✓

    File slack space

    Why this is correct

    File slack space is the gap between the end of a file's logical data and the end of the last allocated cluster in NTFS. This residual space can be filled with arbitrary data without affecting the file's size or visible content, making it invisible in normal directory listings. Since the operating system typically does not overwrite slack space until the cluster is reused, it provides a persistent and covert storage area. This is a classic steganographic method that forensic analysts detect by performing raw sector-level analysis of allocated clusters.

  • ✗

    Volume Shadow Copy

    Why it's wrong here

    Volume Shadow Copy is a Windows service that creates point-in-time snapshots of files and volumes for backup and System Restore. While shadow copies may retain previous iterations of files that an attacker later deleted or modified, their primary purpose is data preservation, not concealment. They are not a hidden storage location because shadow copies themselves are tracked by the OS and can be accessed with forensic tools. Treating them as a hiding method confuses the forensic value of preserved versions with the deliberate act of hiding data.

  • ✓

    Alternate Data Streams (ADS)

    Why this is correct

    Alternate Data Streams (ADS) is an NTFS feature that allows multiple data streams to be attached to a single file, with the main stream holding the visible content. Additional streams can be created and written to without altering the file's displayed size or enabling normal file browsing to show them, providing a stealthy way to embed data or executables. Because many traditional DLP and antivirus tools do not scan ADS, attackers frequently use them to hide malicious payloads. Forensic examiners must parse the $MFT or use specialized utilities like streams.exe to identify extraneous streams.

  • ✗

    Encrypting File System (EFS)

    Why it's wrong here

    Encrypting File System (EFS) is a Windows feature that encrypts file contents using a per-user cryptographic key tied to the user's account. While encryption protects confidentiality, it does not hide the file's existence, name, size, or metadata—those remain visible. Moreover, EFS-encrypted files are clearly marked with an encryption attribute in the file system, making them identifiable to forensic tools. Therefore, EFS is a confidentiality control, not a data-hiding technique.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.