An analyst is examining a Windows 10 system where a user deleted several files containing sensitive data. The analyst needs to recover the file content and determines that the $DATA attribute of the MFT record for one deleted file is resident. What does this indicate about the file's data and its recoverability?
A resident $DATA attribute means the file's content is small enough to fit inside the MFT record. When the file is deleted, the record is marked as free but the data remains until the record is reallocated. Therefore, the content may still be recoverable by parsing the MFT entry.
Why this answer
A resident $DATA attribute means the file's content is stored directly within the MFT record because it is small enough. After deletion, the record is marked free but the data persists until the record is reused. An examiner can parse the MFT entry to recover the content, provided the record has not been overwritten.
Exam trap
The trap here is confusing resident data with external cluster storage, leading an analyst to attempt carving instead of examining the MFT record itself.