
EC-CouncilComputer Hacking Forensic Investigator
Domain 2Objective 1
Understanding Hard Disks and File Systems CHFI Practice Questions (Page 6)
Part of the Storage Media, Acquisition and Anti-Forensics domain, which makes up ~18% of our current practice bank.
37questions here
8free pages
7concepts
Questions 26–30
- 26
A forensic examiner is analyzing a disk image from a Windows 10 workstation. The disk has a GPT partition table with three partitions: an EFI System Partition, a Windows C: drive (NTFS), and a recovery partition. The examiner needs to locate the NTFS boot sector of the C: drive. Which of the following is the most reliable method to find it?
Select an answer first - 27
A forensic examiner is analyzing a hard drive that has been subject to a low-level format. The drive's firmware reports a total of 1,000,000 LBA sectors. The examiner needs to determine the physical geometry of the drive to estimate the number of platters. The drive's documentation states it has 8 heads and 63 sectors per track. What is the approximate number of cylinders on this drive?
Select an answer first - 28
Which of the following is an example of file system metadata that is forensically significant?
Select an answer first - 29
You are examining a disk that uses a GUID Partition Table (GPT). The disk has a protective MBR at sector 0. What is the primary purpose of this protective MBR?
Select an answer first - 30
Which statement correctly describes the difference between CHS and LBA addressing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.