CHFI Storage Forensics and File System Analysis Practice Question
Which TWO of the following tools are commonly used for file carving during forensic investigations?
⚠ Common exam trap
EC-Council often tests the distinction between file carving tools (Foremost, PhotoRec) and memory analysis tools (Volatility, WinPmem) or file system analysis tools (Sleuth Kit), expecting candidates to recognize that carving operates on raw disk data without file system metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Foremost
Foremost (C) is correct because it is a classic file-carving tool that scans raw disk images or unallocated space and reconstructs files by matching known headers, footers, and internal structures defined in its configuration file. PhotoRec (E) is also correct because it performs signature-based carving to recover deleted files from disk images, memory cards, and other media, ignoring the filesystem to extract data by content type. Sleuth Kit (A) is a forensic analysis toolkit for examining filesystem metadata and timelines rather than a dedicated carving tool, WinPmem (B) is a memory acquisition tool for capturing RAM images, and Volatility (D) is a memory forensics framework for analyzing RAM dumps, so none of these are primarily used for file carving.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sleuth Kit
Why it's wrong here
Sleuth Kit (TSK) is a collection of command-line tools that analyze file-system metadata through structures such as the MFT, inodes, and directory entries. Because it relies on metadata to reconstruct files, it cannot perform file carving, which is the low-level extraction of data using content signatures from raw disk partitions. TSK's ils, fls, and icat operate within existing file system structures, while carving requires a separate tool like foremost or scalpel.
- ✗
WinPmem
Why it's wrong here
WinPmem is a memory acquisition driver used to capture the physical RAM of a Windows system, producing a memory image for volatile data analysis. It never reads disk sectors or looks for file signatures, so it is irrelevant to file carving. Its purpose is to preserve live system memory, not to recover files from unallocated space on a disk image.
- ✓
Foremost
Why this is correct
Foremost is a well-known file carver that performs signature-based recovery by scanning raw image files for headers and footers defined in its configuration file, foremost.conf. It recovers files by content, not metadata, making it effective after formatting or file-system damage. Foremost supports many common file types and is a standard tool in Linux forensic distributions for recovering deleted files.
- ✗
Volatility
Why it's wrong here
Volatility is an advanced memory forensics framework that analyzes RAM dumps to extract processes, network connections, registry data, and other volatile artifacts. It does not operate on disk images or raw block devices, so it cannot perform file carving. Its functionality is specifically tied to memory introspection, not to recovering files from unallocated disk storage.
- ✓
PhotoRec
Why this is correct
PhotoRec is a robust file carver included in the TestDisk suite that identifies file structures using signatures and data patterns, rather than relying on file system metadata. It supports a broad range of formats and runs on raw disk images, ignoring the file system to recover deleted files from unallocated sectors. Like foremost, PhotoRec is commonly used with raw disk images when the file system is corrupt or files have been deliberately wiped.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
RAM Analysis
RAM Analysis is the forensic examination of a computer’s volatile memory to uncover evidence of running processes, network connections, malware, and user activity that is lost when the system is powered off.
Key term
Data Carving
Data carving is the process of recovering files and data fragments from a storage device without relying on the file system metadata.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.