Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

Which TWO of the following tools are commonly used for file carving during forensic investigations?

⚠ Common exam trap

EC-Council often tests the distinction between file carving tools (Foremost, PhotoRec) and memory analysis tools (Volatility, WinPmem) or file system analysis tools (Sleuth Kit), expecting candidates to recognize that carving operates on raw disk data without file system metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Foremost

Foremost (C) is correct because it is a classic file-carving tool that scans raw disk images or unallocated space and reconstructs files by matching known headers, footers, and internal structures defined in its configuration file. PhotoRec (E) is also correct because it performs signature-based carving to recover deleted files from disk images, memory cards, and other media, ignoring the filesystem to extract data by content type. Sleuth Kit (A) is a forensic analysis toolkit for examining filesystem metadata and timelines rather than a dedicated carving tool, WinPmem (B) is a memory acquisition tool for capturing RAM images, and Volatility (D) is a memory forensics framework for analyzing RAM dumps, so none of these are primarily used for file carving.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sleuth Kit

    Why it's wrong here

    Sleuth Kit (TSK) is a collection of command-line tools that analyze file-system metadata through structures such as the MFT, inodes, and directory entries. Because it relies on metadata to reconstruct files, it cannot perform file carving, which is the low-level extraction of data using content signatures from raw disk partitions. TSK's ils, fls, and icat operate within existing file system structures, while carving requires a separate tool like foremost or scalpel.

  • ✗

    WinPmem

    Why it's wrong here

    WinPmem is a memory acquisition driver used to capture the physical RAM of a Windows system, producing a memory image for volatile data analysis. It never reads disk sectors or looks for file signatures, so it is irrelevant to file carving. Its purpose is to preserve live system memory, not to recover files from unallocated space on a disk image.

  • ✓

    Foremost

    Why this is correct

    Foremost is a well-known file carver that performs signature-based recovery by scanning raw image files for headers and footers defined in its configuration file, foremost.conf. It recovers files by content, not metadata, making it effective after formatting or file-system damage. Foremost supports many common file types and is a standard tool in Linux forensic distributions for recovering deleted files.

  • ✗

    Volatility

    Why it's wrong here

    Volatility is an advanced memory forensics framework that analyzes RAM dumps to extract processes, network connections, registry data, and other volatile artifacts. It does not operate on disk images or raw block devices, so it cannot perform file carving. Its functionality is specifically tied to memory introspection, not to recovering files from unallocated disk storage.

  • ✓

    PhotoRec

    Why this is correct

    PhotoRec is a robust file carver included in the TestDisk suite that identifies file structures using signatures and data patterns, rather than relying on file system metadata. It supports a broad range of formats and runs on raw disk images, ignoring the file system to recover deleted files from unallocated sectors. Like foremost, PhotoRec is commonly used with raw disk images when the file system is corrupt or files have been deliberately wiped.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.