CHFI Storage Forensics and File System Analysis Practice Question
Which TWO of the following tools are commonly used for file carving in forensic investigations?
⚠ Common exam trap
EC-Council often tests the distinction between tools that perform file carving natively (PhotoRec, Foremost) versus tools that are forensic suites or network analyzers, leading candidates to mistakenly select Autopsy or EnCase because they associate them with forensic analysis in general.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PhotoRec
PhotoRec (B) is a free, open-source file carving utility from the TestDisk suite that recovers files by scanning raw disk images or devices for known file signatures (headers/footers), ignoring the filesystem, which is exactly what file carving means. Foremost (C) is another classic carving tool originally developed for the U.S. Air Force OSI, which uses a configurable header/footer signature database (foremost.conf) to extract files from disk images and is widely cited in forensic curricula. Autopsy (A) is a full digital forensics platform (a GUI front-end to The Sleuth Kit) that performs timeline, keyword, and artifact analysis; although it can invoke carving, it is not primarily a carving tool. EnCase (D) is a commercial forensic suite for imaging and analysis rather than a dedicated carver. Wireshark (E) is a network protocol analyzer that captures and inspects packet traffic, unrelated to recovering files from storage media.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Autopsy
Why it's wrong here
Autopsy is a digital forensics platform that provides a graphical interface for The Sleuth Kit (TSK) and integrates various modules, including file carving via external tools like PhotoRec. However, carving is only one of many analysis functions within Autopsy, which also performs timeline analysis, hash filtering, keyword search, and artifact extraction. It is not categorized as a dedicated file carving tool; rather, it is an all-encompassing forensic suite that can invoke carvers. Thus, while Autopsy can support carving workflows, it is not itself a carving tool.
- ✓
PhotoRec
Why this is correct
PhotoRec is a purpose-built file carving utility that operates by reading raw disk blocks and identifying known file signatures, independent of the filesystem metadata. It recovers a wide range of file types (e.g., JPEG, PDF, Office documents, archives) by scanning for magic numbers and reconstructing data based on internal structure. PhotoRec is part of the TestDisk suite and is widely used in data recovery and forensic investigations because it works on corrupted or formatted media. Its design as a standalone carving engine makes it a canonical example of a file carving tool.
- ✓
Foremost
Why this is correct
Foremost is a dedicated file carving tool originally developed by the United States Air Force Office of Special Investigations. It performs carving by scanning for predefined file headers and footers defined in a configuration file (foremost.conf), then extracts the data between those boundaries to reconstruct files. Foremost supports many common file formats and can process raw disk images or logical files, making it a staple in forensic toolkits. As a specialized utility focused solely on carving based on structural signatures, it is commonly listed alongside PhotoRec as a primary carving tool.
- ✗
EnCase
Why it's wrong here
EnCase is an enterprise-grade forensic software suite that includes acquisition, analysis, and reporting capabilities, with file carving available as one of its many built-in features. Its carving module can recover deleted files from unallocated space using signature analysis, but that does not make EnCase a carving tool itself. EnCase is fundamentally a comprehensive digital investigation platform, often used for evidence discovery, forensic imaging, and chain-of-custody management. Unlike PhotoRec or Foremost, EnCase is not commonly referenced as a dedicated carving utility; it is a full forensic solution that happens to offer carving.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer used to capture and interactively browse traffic running on a computer network. It decodes packets according to protocol specifications and provides detailed information about network communications, but it has no capability for recovering files from disk images or unallocated space via file signatures. Because its domain is live network traffic, not static filesystem analysis, Wireshark is entirely unrelated to file carving. This makes it an incorrect answer for a question seeking tools used for file carving.
Go deeper
Related to this question
Learn chapter
Forensic Tools and Laboratory Setup
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.