Types of Slack Space in Forensic Investigations
Which TWO of the following are types of slack space that can contain forensic evidence?
⚠ Common exam trap
EC-Council often tests the distinction between 'volume slack' and 'RAM slack' as the two correct types, while distractors like 'swap space' or 'index slack' are common misconceptions that candidates mistake for legitimate slack space categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Volume slack
Volume slack (A) is correct because it is the unused space remaining at the end of a volume after the last allocated cluster, which can retain residual data from deleted or resized partitions and is a recognized forensic artifact. RAM slack (E) is correct because it is the portion of the final sector of a file that is padded with data from memory when the file does not fill the sector, potentially capturing volatile memory contents that persist on disk. Index slack (B) is not a standard slack-space type; index entries are metadata structures, not slack areas. Swap space (C) is a paging file area, not a category of file-system slack, though it can hold evidence it is not classified as slack space. Buffered slack (D) is not a recognized forensic slack-space term.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Volume slack
Why this is correct
Volume slack is the unused space at the end of a filesystem volume that is not mapped to any allocated cluster. Because the volume's total size is rarely an exact multiple of the cluster size, a residual area remains after the last cluster. This area may retain remnants of old data from a previous filesystem or partition, making it valuable in forensic investigations.
- ✗
Index slack
Why it's wrong here
Index slack is not a recognized type of slack space in digital forensics. Filesystems do maintain index structures such as directory entry tables or NTFS metadata files, but any leftover bytes inside those structures are part of the filesystem metadata, not a distinct slack-space category. Standard forensic taxonomy identifies RAM slack and volume slack (and optionally file slack), but index slack is invalid.
- ✗
Swap space
Why it's wrong here
Swap space is an operating system-controlled region used for paging virtual memory to disk, not a form of slack space. Unlike slack space, which consists of unused bytes within an allocated cluster or at the volume edge, swap space is an intentionally reserved partition or file. Although swap files can leak memory contents, they are not classified as slack space in forensic terminology.
- ✗
Buffered slack
Why it's wrong here
Buffered slack is a fabricated term and not a recognized slack-space type. It could be confused with the kernel's buffer cache, which holds recently accessed disk blocks in memory, but that cache is a RAM-based mechanism, not a disk-level area. Slack space is always defined by filesystem cluster geometry, so buffered slack does not exist as a forensic classification.
- ✓
RAM slack
Why this is correct
RAM slack is the unused portion of the last sector in a file's final cluster, extending from the end of the file's logical content to the end of that sector. When the operating system writes a file to disk, it copies entire sectors from a memory buffer, so the bytes beyond the file's logical end are filled with whatever was in RAM. This can include sensitive in-memory data, making RAM slack a legitimate and forensically significant type of slack space.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.