A candidate must interpret MACB timestamp combinations across NTFS and ext4 artifacts and explain what each change indicates. The most important thing is distinguishing legitimate system updates from anti-forensic manipulation by cross-checking $STANDARD_INFORMATION against $FILE_NAME timestamps and inode metadata.
Start practicing
File System Timeline Artifact Analysis — choose a session length
Free · No account required
Domain overview
This GCFA domain covers reconstructing activity from file system metadata across NTFS and ext4. Candidates use fls, mactime, and $MFT parsing to interpret MACB timestamps, $STANDARD_INFORMATION versus $FILE_NAME discrepancies, and anti-forensic timestamp manipulation. Questions present artifact combinations and require correct interpretation of what each timestamp change implies about user or system activity.
Exam objectives
Interpreting ext4 inode ctime, atime, and mtime changes via fls and mactime output
Comparing NTFS $STANDARD_INFORMATION MACB timestamps against $FILE_NAME timestamps for discrepancies
Using $MFT record 0 and $MFT metadata to anchor NTFS timeline construction
Recognizing anti-forensic techniques such as timestomping and secure deletion that alter file system timelines
Assuming a changed ctime always means content modification, when metadata-only changes like permissions or ownership also update ctime.
Treating $STANDARD_INFORMATION timestamps as authoritative without checking $FILE_NAME, which timestomping tools often leave inconsistent.
Overlooking $MFT record 0 or $MFTMirr when building timelines, missing metadata that establishes the volume's baseline.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Refer to the exhibit. What can be inferred about the file activity?
2Which TWO of the following actions are considered 'anti-forensic' techniques that directly impact file system timeline analysis?
3An analyst is examining a file that was deleted. Why is the 'File Name' (FN) attribute in the MFT still potentially readable?
4Which of the following is true regarding the 'MFT Change' timestamp?
5What is the primary function of the $LogFile in an NTFS file system?
6An investigator analyzing an NTFS volume notices that a file's $STANDARD_INFORMATION MACB timestamps significantly differ from its $FILE_NAME timestamps. The $FILE_NAME modification time predates the $STANDARD_INFORMATION modification time. What is the most reliable forensic interpretation of this discrepancy?
7An investigator is analyzing ext4 file system timelines extracted via fls and mactime. They notice that an inode's ctime was updated recently, but the atime and mtime remained unchanged. What does this specific combination of inode timestamp changes typically indicate in a Linux environment?
8An investigator is analyzing MACB timelines on a Windows system and needs to differentiate between a file being copied versus being moved within the same NTFS volume. Which timeline artifact behavior distinguishes an intra-volume file move from a file copy operation?
9An analyst is examining an NTFS volume and notices a discrepancy where the $Standard_Information attribute modification time is earlier than the $File_Name attribute modification time. What does this specific pattern indicate about the file's history?
10When analyzing the $LogFile in NTFS, what is the significance of the undo and redo operations recorded in the transaction logs for timeline reconstruction?
11An investigator is examining a Windows 10 workstation's NTFS volume with Sleuth Kit tools. They run fls against the volume and observe that a deleted file's MFT entry still shows a valid $FILE_NAME attribute referencing the parent directory, but the $DATA attribute's resident content is now zero-filled. Which interpretation of this artifact is MOST accurate for the timeline?
12During an investigation of an ext4 file system, an analyst runs `fls -r -m /` and `mactime` to build a body file. The analyst observes that many deleted files show a dtime in the body file, but the mactime timeline places those dtime entries at the time the file was deleted. A colleague claims that dtime in ext4 always represents the time the inode was last modified. Which statement correctly describes ext4 dtime behavior in this timeline context?
13During a Windows 10 intrusion investigation, an analyst uses fls on a raw NTFS image and observes that for a suspicious executable, the $FILE_NAME creation timestamp is 2023-08-10 14:22:01, while the $STANDARD_INFORMATION creation timestamp is 2023-08-10 14:22:01 as well, but the $STANDARD_INFORMATION modified timestamp is 2023-08-10 14:22:01 and the $FILE_NAME modified timestamp is 2023-08-10 14:22:01. However, the $MFT record header's last modification time (the MFT entry itself) is 2023-08-10 14:25:33. What is the most likely explanation for the discrepancy between the MFT record modification time and the file's timestamps?
14An analyst is reviewing an NTFS file system timeline and notices that a file's $STANDARD_INFORMATION modified timestamp is 2024-01-15 10:00:00, while its $FILE_NAME modified timestamp is 2024-01-15 09:55:00. The file's $MFT record shows a USN journal entry indicating a rename operation at 09:54:00. There is no other metadata. Which of the following is the most likely explanation for the 5-minute difference between the two modified timestamps?
15An examiner is reviewing an APFS volume from a macOS 13 system. Using a timeline tool that parses APFS metadata, the analyst observes a file whose inode has an added date (birth time) earlier than its modified time, and the file's data stream shows a sparse extent. The case requires establishing the earliest credible creation time for the file. Which APFS attribute should the analyst rely on as the file's creation time?
16A forensic analyst is examining a Windows 10 system and finds a prefetch file named `CMD.EXE-1234ABCD.pf`. The analyst wants to determine the last time the program was executed. Which timestamp in the prefetch file should the analyst use?
17A forensic analyst is examining an ext4 file system image from a Linux server. Using fls and istat from The Sleuth Kit, the analyst sees a deleted file whose inode still contains block pointers that now point to blocks reallocated to another file. The analyst wants to determine whether the deleted file's content can be recovered intact. Which ext4 condition best explains why the content is likely unrecoverable?
18A forensic analyst is creating a timeline from an NTFS volume and wants to include the $MFT's record number 0, which contains metadata about the MFT itself. What is the primary purpose of including this record in the timeline?
19During an investigation of a Windows system, an analyst is reviewing a supertimeline and observes that a suspicious executable's $STANDARD_INFORMATION timestamps are all set to a date years before the operating system was installed, while its $FILE_NAME timestamps reflect the actual installation period. The analyst suspects timestomping. Which conclusion is most defensible based on NTFS timestamp behavior?
20An analyst is using The Sleuth Kit to analyze an NTFS image. They run `fls -r -m C:/` to generate a body file and then `mactime -b bodyfile -d` to produce a timeline. They notice that the timeline includes entries for files with a '$' prefix, such as $MFT, $LogFile, and $Bitmap. What is the most appropriate action for the analyst to take regarding these entries?
A candidate must interpret MACB timestamp combinations across NTFS and ext4 artifacts and explain what each change indicates. The most important thing is distinguishing legitimate system updates from anti-forensic manipulation by cross-checking $STANDARD_INFORMATION against $FILE_NAME timestamps and inode metadata.
The Courseiva GCFA question bank contains 20 questions in the File System Timeline Artifact Analysis domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the File System Timeline Artifact Analysis domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included