CHFI Storage Forensics and File System Analysis Practice Question
Which TWO tools are specifically designed for file carving (recovering files based on signatures) and are commonly used in digital forensics?
⚠ Common exam trap
EC-Council often tests the distinction between dedicated file carving tools (Scalpel, Foremost) and broader forensic suites (EnCase, Autopsy) that include carving as a secondary feature, leading candidates to incorrectly select the more well-known commercial tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scalpel
Scalpel (B) is correct because it is a signature-based file carving tool derived from Foremost that reads a configurable header/footer database to extract files from raw disk images or unallocated space without relying on filesystem metadata. Foremost (C) is correct because it was originally developed for the U.S. Air Force OSI and carves files by matching file headers and footers (e.g., JPEG, PDF, ZIP) in disk images, making it a canonical carving utility in digital forensics. Volatility (A) is a memory forensics framework for analyzing RAM dumps, not a file carver. EnCase (D) is a full commercial forensic suite that can recover files via filesystem parsing and some carving, but it is not specifically designed as a signature-based carving tool. Autopsy (E) is a graphical forensic platform that integrates carving modules (often via Scalpel or its own ingest modules) but is not itself a dedicated carving tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Volatility
Why it's wrong here
Volatility is a Python-based memory forensics framework designed to analyze volatile RAM captures, extracting running processes, network connections, loaded kernel modules, and registry data from memory. It does not parse storage media or recover files based on content signatures, so it has no file carving functionality at all. Therefore it is incorrect because its purpose is volatile memory analysis, not carving files from unallocated disk space.
- ✓
Scalpel
Why this is correct
Scalpel is a dedicated file carving tool written in C, originally derived from Foremost but completely rewritten for speed and efficiency. It uses a configuration file (carve.conf) to define binary header and footer signatures, then scans raw byte streams to extract files without needing filesystem metadata. Its entire purpose is file carving, making it a correct answer.
- ✓
Foremost
Why this is correct
Foremost is a classic file carving utility originally developed by the US Air Force Office of Special Investigations. It sequentially reads a disk image or raw device, matching file headers and footers defined in its configuration to recover data from unallocated space or corrupted filesystems. Because it was purpose-built for this exact task, it is a correct answer.
- ✗
EnCase
Why it's wrong here
EnCase is a comprehensive commercial forensic suite that provides disk imaging, evidence processing, keyword search, scripting, reporting, and a proprietary evidence file format. While it includes a file carving module as part of its evidence processing pipeline, carving is only one feature among many, not the tool's primary design focus. Therefore EnCase is incorrect because it is a general-purpose forensic platform rather than a specifically designed carving tool.
- ✗
Autopsy
Why it's wrong here
Autopsy is an open-source graphical digital forensics platform built on The Sleuth Kit (TSK) that offers timeline analysis, hash filtering, keyword search, and ingest modules. It can perform file carving through an ingest module that invokes external tools like PhotoRec or uses built-in unallocated space carving, but this is an ancillary function within a broader framework. Thus it is not specifically designed for carving, making it an incorrect choice.
Go deeper
Related to this question
Learn chapter
Legal and Ethical Issues in Digital Forensics
Key term
RAM Analysis
RAM Analysis is the forensic examination of a computer’s volatile memory to uncover evidence of running processes, network connections, malware, and user activity that is lost when the system is powered off.
Key term
Volatility Framework
An open-source memory forensics tool used to extract digital evidence from a computer's RAM (random access memory).
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.