โ† All CHFI Flashcard Decks

Hard Disk and File Systems Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Hard Disk and File Systems flashcards as text
  1. Which Windows registry hive stores the most recently accessed files and applications, useful for establishing user activity timelines?

    Answer: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

    The RecentDocs registry key tracks files recently opened by the user in Windows Explorer, providing a timeline of file access.

  2. In NTFS, what are Alternate Data Streams (ADS) and why are they forensically significant?

    Answer: Additional data attached to a file without appearing in its normal size, used to hide data

    ADS allows data to be attached to an NTFS file under a different stream name and is invisible to Windows Explorer, making it a common data-hiding technique.

  3. What does the term 'inode' refer to in Linux/ext4 file systems?

    Answer: A data structure containing file metadata such as permissions, timestamps, and block pointers

    An inode is a data structure in ext file systems that stores all metadata about a file except its name, including ownership, permissions, and pointers to data blocks.

  4. A forensic examiner uses the 'dd' command to image a drive. What is the significance of the 'bs' (block size) parameter?

    Answer: It determines the amount of data read and written per operation, affecting speed and sector alignment

    The block size (bs) parameter controls how many bytes dd reads and writes at once; aligning it to the disk's sector size (512 or 4096 bytes) improves accuracy and performance.

  5. What is the Host Protected Area (HPA) on a hard disk drive?

    Answer: A hidden area at the end of the disk that is excluded from normal OS disk size reporting

    The HPA is a hidden region defined by ATA standard SET MAX ADDRESS commands that the BIOS and OS cannot normally detect, commonly used to hide data from forensic tools.

  6. Which tool is commonly used in Linux forensics to recover deleted files from an ext4 file system by scanning unallocated inode entries?

    Answer: extundelete

    extundelete is a Linux tool that analyzes ext3/ext4 journal and inode tables to recover deleted files from unallocated space.

  7. What does the MFT entry attribute $DATA contain in NTFS?

    Answer: The actual file content or data runs pointing to the file's data clusters

    The $DATA attribute in an MFT entry either contains the file's data directly (resident) or data runs that map to the clusters holding the file's content (non-resident).