Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

Which TWO of the following are valid methods for hiding data on an NTFS volume without using third-party tools? (Select 2)

⚠ Common exam trap

Candidates often confuse data hiding with data protection or access control, incorrectly selecting EFS (encryption) or symbolic links as hiding methods, when the CHFI exam specifically tests native NTFS features that conceal data from normal file system views without altering file attributes or permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Slack space (file slack or volume slack)

Option C is correct because NTFS allocates disk space in clusters, and when a file's logical size is smaller than the allocated cluster(s), the unused bytes form file slack (and unused clusters at the end of the volume form volume slack); data written into that slack is not visible through normal file reads and requires no third-party tool—just native OS utilities. Option D is correct because NTFS natively supports Alternate Data Streams, allowing extra data to be attached to a file via syntax like 'type secret > file.txt:stream', and this stream is not shown by default in Explorer or a standard 'dir' listing, making it a built-in hiding method. Option A is not a hiding method—a symbolic link is simply a reparse point that redirects to a target, and the link itself is visible; it does not conceal data. Option B, EFS encryption, protects confidentiality but does not hide the file's existence, as the file and its metadata remain visible. Option E, the $Recycle.bin folder, is a normal system folder for deleted items and does not provide a native concealment mechanism beyond ordinary file attributes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Creating a symbolic link to a hidden file

    Why it's wrong here

    A symbolic link (symlink) is a filesystem object that merely references another file or directory, providing an alternate path to the target. It does not conceal the target's existence; both the link and the target remain visible in directory listings and discoverable via standard enumeration. Hiding data requires removing the file from view or obfuscating its content, which a symlink does not accomplish.

  • ✗

    Encrypting the file with EFS

    Why it's wrong here

    Encrypting File System (EFS) is a Windows transparent encryption feature that converts file contents from plaintext to ciphertext using a per-user key. While EFS protects confidentiality from unauthorized readers, it does not hide the file's name, size, timestamps, or location, and the encrypted attribute is visible in file metadata. An investigator can easily identify the presence of encrypted files, making EFS a confidentiality mechanism rather than a data-hiding one.

  • ✓

    Slack space (file slack or volume slack)

    Why this is correct

    Slack space arises because files are stored in fixed-size clusters, and a file rarely fills the final cluster completely, leaving unused bytes (file slack) or gaps between allocated clusters (volume slack). These residual areas can be overwritten with hidden data without altering the file's apparent size or its directory entry, since the OS does not touch slack during normal operations. This creates a covert storage location that persists until the cluster is reused, making it a standard technique for hiding forensic evidence.

  • ✓

    Alternate Data Streams (ADS)

    Why this is correct

    Alternate Data Streams (ADS) is an NTFS feature that allows a file to contain multiple named data streams, with the main stream holding visible content while additional streams store supplementary data. These streams are not displayed in standard directory listings or Explorer views, so a user can attach hidden bytes to a legitimate file without affecting its apparent content. Data written to an ADS is fully accessible to processes that use the stream syntax, but invisible to casual inspection, making it a classic data-hiding vector.

  • ✗

    Using the $Recycle.bin folder

    Why it's wrong here

    The $Recycle.bin folder is a system container that Windows uses to hold deleted items before permanent removal, preserving the original file's path, deletion timestamp, and size in its $I index. It is a standard, visible part of the filesystem and is highly scrutinized by forensic examiners because it retains artifacts of user deletions. Using it to 'hide' data would be counterproductive, as the Recycle Bin creates a detailed audit trail rather than concealing the data's existence.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.