Courseiva

Types of Slack Space in Forensic Investigations

Which TWO of the following are types of slack space that can contain forensic evidence?

⚠ Common exam trap

EC-Council often tests the distinction between 'volume slack' and 'RAM slack' as the two correct types, while distractors like 'swap space' or 'index slack' are common misconceptions that candidates mistake for legitimate slack space categories.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Volume slack

Volume slack (A) is correct because it is the unused space remaining at the end of a volume after the last allocated cluster, which can retain residual data from deleted or resized partitions and is a recognized forensic artifact. RAM slack (E) is correct because it is the portion of the final sector of a file that is padded with data from memory when the file does not fill the sector, potentially capturing volatile memory contents that persist on disk. Index slack (B) is not a standard slack-space type; index entries are metadata structures, not slack areas. Swap space (C) is a paging file area, not a category of file-system slack, though it can hold evidence it is not classified as slack space. Buffered slack (D) is not a recognized forensic slack-space term.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Volume slack

    Why this is correct

    Volume slack is the unused space at the end of a filesystem volume that is not mapped to any allocated cluster. Because the volume's total size is rarely an exact multiple of the cluster size, a residual area remains after the last cluster. This area may retain remnants of old data from a previous filesystem or partition, making it valuable in forensic investigations.

  • ✗

    Index slack

    Why it's wrong here

    Index slack is not a recognized type of slack space in digital forensics. Filesystems do maintain index structures such as directory entry tables or NTFS metadata files, but any leftover bytes inside those structures are part of the filesystem metadata, not a distinct slack-space category. Standard forensic taxonomy identifies RAM slack and volume slack (and optionally file slack), but index slack is invalid.

  • ✗

    Swap space

    Why it's wrong here

    Swap space is an operating system-controlled region used for paging virtual memory to disk, not a form of slack space. Unlike slack space, which consists of unused bytes within an allocated cluster or at the volume edge, swap space is an intentionally reserved partition or file. Although swap files can leak memory contents, they are not classified as slack space in forensic terminology.

  • ✗

    Buffered slack

    Why it's wrong here

    Buffered slack is a fabricated term and not a recognized slack-space type. It could be confused with the kernel's buffer cache, which holds recently accessed disk blocks in memory, but that cache is a RAM-based mechanism, not a disk-level area. Slack space is always defined by filesystem cluster geometry, so buffered slack does not exist as a forensic classification.

  • ✓

    RAM slack

    Why this is correct

    RAM slack is the unused portion of the last sector in a file's final cluster, extending from the end of the file's logical content to the end of that sector. When the operating system writes a file to disk, it copies entire sectors from a memory buffer, so the bytes beyond the file's logical end are filled with whatever was in RAM. This can include sensitive in-memory data, making RAM slack a legitimate and forensically significant type of slack space.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.