
EC-CouncilComputer Hacking Forensic Investigator
Domain 2Objective 1
Understanding Hard Disks and File Systems CHFI Practice Questions (Page 4)
Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.
37questions here
8free pages
7concepts
Questions 16–20
- 16
A forensic examiner is analyzing a disk image from a Linux system that uses ext4. The examiner needs to recover a deleted file. The file was stored in a directory that has been deleted as well. Which of the following is the most likely place to find remnants of the deleted file's data?
Select an answer first - 17
A forensic examiner is comparing two file systems: FAT32 and NTFS. The examiner needs to identify a key difference that affects forensic analysis. Which of the following is a true difference?
Select an answer first - 18
A forensic examiner is documenting the physical layout of a hard disk. They note that the disk has 4 platters, 8 heads, and 1024 cylinders, with 63 sectors per track. What is the total storage capacity of this disk in bytes, assuming each sector is 512 bytes?
Select an answer first - 19
In a typical FAT file system, which structure contains the list of file names, starting cluster numbers, and attributes for files in a directory?
Select an answer first - 20
You are comparing the forensic artifacts of a file stored on NTFS and the same file stored on ext4. Which of the following differences is most significant for forensic analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.