
EC-CouncilComputer Hacking Forensic Investigator
Domain 2Objective 1
Understanding Hard Disks and File Systems CHFI Practice Questions (Page 1)
Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.
37questions here
8free pages
7concepts
Questions 1–5
- 1
A forensic examiner is analyzing a disk image from a Linux system. The disk has a GPT partition table. The examiner needs to identify the location of the root file system partition. Which of the following is the most reliable method?
Select an answer first - 2
Which file system is natively used by modern Linux distributions and supports features such as journaling, extended attributes, and large file sizes?
Select an answer first - 3
A forensic examiner is analyzing a hard disk that has a reported geometry of 16,383 cylinders, 16 heads, and 63 sectors per track. The disk uses LBA addressing. The examiner needs to determine the total number of sectors on the disk. Which calculation is correct?
Select an answer first - 4
An examiner is investigating a case involving a suspect who allegedly edited a document on an NTFS volume. The file's $STANDARD_INFORMATION attribute shows a last modified time of 10:00 AM, but the $FILE_NAME attribute shows a last modified time of 9:45 AM. Which of the following is the most likely explanation for this discrepancy?
Select an answer first - 5
A forensic examiner is analyzing a disk image from a Windows 10 system. The disk has a GPT partition table with an EFI System Partition (ESP) and a Windows C: drive (NTFS). The examiner needs to locate the boot sector of the C: drive. Which of the following is the most reliable method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.