Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 2Objective 1

Understanding Hard Disks and File Systems CHFI Practice Questions (Page 3)

Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.

37questions here
8free pages
7concepts

Questions 11–15

  1. 11application · medium

    A forensic examiner is analyzing a hard disk that was used to store sensitive documents. The documents were deleted using the Shift+Delete command in Windows, which bypasses the Recycle Bin. The examiner wants to recover the deleted files. Which of the following is the most accurate statement about the deleted data?

    Select an answer first
  2. 12foundation · easy

    In LBA addressing, how is a logical block address mapped to a physical disk location?

    Select an answer first
  3. 13foundation · easy

    What is the primary purpose of a file system on a storage device?

    Select an answer first
  4. 14application · medium

    During a forensic examination of a FAT32 USB drive, an examiner finds a deleted file that was 2,500 bytes in size. The cluster size is 4,096 bytes. The file's directory entry shows the starting cluster and the file size. Which of the following best describes the data that remains on the disk and its forensic significance?

    Select an answer first
  5. 15foundation · easy

    Which of the following is a key advantage of the GUID Partition Table (GPT) over the traditional Master Boot Record (MBR) partitioning scheme?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.