Filesystem Forensics and Data Recovery Questions

Disk and file-system internals for forensic examination and data recovery: NTFS/ext4/APFS/FAT structures (MFT, journaling, inodes), file carving, slack and unallocated space, deleted-file recovery, SSD/TRIM and wear-leveling effects on recoverability, RAID reconstruction, and acquisition/analysis of damaged or encrypted media. Distinct from OS-level artifact analysis (registry, Prefetch, event logs, memory/LSASS, persistence mechanisms) and from timeline construction across sources, which are covered by forensic-artifact-analysis-and-timeline-reconstruction.

HardTechnical
53 practiced

A file was deleted three days ago on a system that's still in active use, writing a few gigabytes of new data a day, with roughly 15% free space remaining. How would you reason about the odds that the file's data clusters haven't been overwritten yet, and what would you actually tell the client about the chances of recovery?

HardTechnical
42 practiced

A suspect used BitLocker and the disk shows signs of wiped container headers. Propose a forensic methodology to attempt recovery of residual header fragments, backup header locations, or potential key material. Include technical steps (search signatures, slack, registry/AD backups, TPM artifacts), legal channels (recovery key requests), and limitations where cryptographic protection precludes recovery.

HardTechnical
48 practiced

You're carving files from unallocated space where the headers and footers have been overwritten, so plain signature matching won't find them. How would you go about detecting and reconstructing files without a header or footer to search for, and how would you keep the false-positive rate under control?

HardTechnical
46 practiced

TRIM is enabled on the SSD you're examining, so the usual 'unallocated space still holds the old data' assumption doesn't hold. You have options ranging from software-level recovery on a logical image up through invasive hardware-level techniques. How would you decide how far up that ladder to go for a given case, and what are you weighing at each step: success likelihood, risk of destroying the evidence, the expertise required, and chain-of-custody?

MediumTechnical
45 practiced

Explain the TRIM command and SSD garbage collection behavior. Discuss how these features shorten the window for recovering deleted files on flash storage, and describe practical steps an examiner can take during acquisition to maximize recovery chances from an SSD or NVMe device.

Unlock Full Question Bank

Get access to all 49 Filesystem Forensics and Data Recovery interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.