You must be able to build a MACB file system timeline and correctly interpret each timestamp's meaning and reliability. The most important thing is knowing which timestamps are trustworthy versus user-modifiable, and filtering super-timeline output before drawing conclusions.
Start practicing
Introduction to File System Timeline Forensics — choose a session length
Free · No account required
Domain overview
This domain covers building and interpreting file system timelines for forensics, focusing on NTFS and ext4 metadata, MACB timestamp semantics, and tools like log2timeline, Plaso, and The Sleuth Kit. Questions test whether you can extract, filter, and reason about timestamps rather than merely generate a timeline.
Exam objectives
Extracting MACB timestamps from NTFS $STANDARD_INFORMATION and $FILE_NAME attributes
Using log2timeline/Plaso to build super-timelines and filter output for relevance
Interpreting ext4 timestamps via The Sleuth Kit fls and istat output
Recognizing time skew, clock drift, and timezone effects in timeline data
Assuming $STANDARD_INFORMATION timestamps are reliable; they are easily modified by user-mode tools and can be forged.
Treating every access time as proof of user interaction, ignoring atime update policies and filesystem mount options.
Forgetting to normalize timezones and clock skew, producing timelines with misordered or misleading events.
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a forensic investigation of an NTFS volume, an analyst notices that the $MFT record for a suspicious executable shows a modified time earlier than its creation time. What does this specific anomaly typically indicate?
2An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?
3When creating a super-timeline using tools like log2timeline, why is it critical to filter the output data?
4An investigator notices that a file's 'Birth' time is later than its 'Modification' time. What is the most likely forensic explanation for this phenomenon?
5In the context of forensic timeline analysis, what does the term 'Time Skew' refer to?
6What is the primary function of the $LogFile in NTFS when reconstructing a timeline?
7Why should a forensic analyst avoid using the 'Last Accessed' time as the primary indicator for a file's usage?
8Which of these is the primary limitation of using a file system 'Birth' time as a definitive event marker?
9An analyst is examining an NTFS volume and notices that a file's MFT entry shows a modification time earlier than its creation time. What is the most likely cause for this anomaly?
10When performing timeline analysis on a Linux system, which file is the most critical to examine to reconstruct user login and logout history?
11Which of the following describes the 'MAC' in MACB times during timeline analysis?
12Why might an analyst prefer using 'Super-Timeline' creation tools, such as log2timeline, over manual collection of file system timestamps?
13During a forensic investigation of a Windows 10 workstation, an analyst reviews the NTFS Master File Table (MFT) and notices that the $STANDARD_INFORMATION timestamps for a suspicious file are all dated 2023-08-15, but the $FILE_NAME timestamps are dated 2024-01-20. The file is located in C:\Users\Public\Downloads. Which of the following best explains this discrepancy?
14An analyst acquires a forensic image of a Windows 10 NTFS volume using a write blocker and now needs to build a file system timeline. The analyst wants to include the $STANDARD_INFORMATION timestamps but also wants to detect timestomping by comparing them with the $FILE_NAME timestamps. Which tool should the analyst use to extract both timestamp sets from the MFT and generate a bodyfile for timeline creation?
15A forensic analyst is examining a Linux ext4 file system and wants to determine when a file's metadata (such as permissions or ownership) was last changed. Which timestamp should they examine?
16An investigator is preparing to analyze a Windows 10 workstation's NTFS volume using a forensic tool that reads the master file table (MFT) directly. The goal is to build a timeline that includes timestamps for files that were deleted before the acquisition. Which artifact should the investigator primarily rely on to recover timestamps for deleted files?
17An investigator is analyzing a Windows 10 system and needs to correlate file system timestamps with other artifacts to build a comprehensive timeline. Which two of the following Windows artifacts can provide additional temporal context when combined with NTFS timestamps? (Choose two.)
18An investigator is building a file system timeline for an NTFS volume from a Windows 10 workstation. The user claims a file was copied to an external drive at 14:00, but the file's NTFS Standard Information Attribute shows only a modification timestamp of 13:45. Which NTFS artifact should the investigator examine to determine when the filename was actually created or renamed on the volume?
19During a forensic examination of an NTFS volume, an analyst notices that a file's $STANDARD_INFORMATION timestamps show a modification time of 2023-04-01 10:00:00, but the $FILE_NAME timestamps show a modification time of 2023-03-15 14:30:00. The file is not a system file and has not been renamed. What is the most likely explanation for this discrepancy?
20An investigator is adding NTFS USN change journal records to a file system timeline on a Windows 10 workstation. The journal was captured live with fsutil usn readjournal and shows a record with Reason value 0x00000100 (DATA_OVERWRITE) for a user document. The investigator wants to determine whether the file content was actually altered at that moment. Which statement best describes what the USN record establishes?
21A forensic analyst is building a timeline from an NTFS volume and wants to include the time when a file's metadata was last changed, such as permission modifications. Which timestamp should the analyst focus on to capture this event?
22An analyst is building a file system timeline from an NTFS volume and is deciding which timestamps to extract from the $STANDARD_INFORMATION attribute. A colleague suggests that the four timestamps in $STANDARD_INFORMATION are the only relevant times. Which statement correctly describes the relationship between $STANDARD_INFORMATION and $FILE_NAME timestamps?
23During a forensic investigation of a Windows 10 system, an analyst observes that a file's $STANDARD_INFORMATION creation timestamp is 2020-01-01 10:00:00, while its $FILE_NAME creation timestamp is 2020-01-01 10:00:05. The system time zone is UTC-5. The analyst also notes that the file's $STANDARD_INFORMATION modification timestamp is 2020-01-01 10:00:00. What is the most likely explanation for the 5-second difference between the creation timestamps?
24A forensic analyst is creating a timeline from a Windows 10 workstation using fls and mactime from The Sleuth Kit. The analyst notices that the bodyfile contains entries with timestamps that appear to be off by several hours compared to the wall-clock time the incident was reported. The system is known to be set to UTC in the BIOS. Which action best ensures the timeline is correctly aligned for reporting?
25During a timeline review of an NTFS volume, an analyst observes that a file's $STANDARD_INFORMATION modification time is several days earlier than its $FILE_NAME modification time, and the $STANDARD_INFORMATION creation time is also earlier than the $FILE_NAME creation time. The file is a suspected malware dropper. Which conclusion is best supported by this pattern?
26A forensic analyst is using a tool to generate a file system timeline from an NTFS volume. The tool outputs timestamps with nanosecond precision, but the analyst knows that NTFS stores timestamps with 100-nanosecond resolution. What is the most likely reason for the discrepancy?
27A forensic analyst is building a file system timeline from an NTFS volume and wants to ensure it includes reliable evidence of file creation and deletion events. Which two artifacts should the analyst prioritize to capture these events? (Choose two.)
28An investigator is analyzing a Linux ext4 file system and needs to determine when a file's content was last modified. The file's inode contains ctime, mtime, and atime fields. Which timestamp should the investigator use to answer this specific question?
29A forensic analyst is examining an NTFS volume and wants to identify potential timestomping. Which TWO artifacts should the analyst compare to detect inconsistencies in file timestamps? (Choose two.)
30An investigator is analyzing an NTFS volume from a Windows Server 2016 system that was recently compromised. The attacker used a tool to modify file timestamps to evade detection. The investigator notices that the $STANDARD_INFORMATION timestamps for a suspicious executable are all set to 2018-01-01, while the $FILE_NAME timestamps remain at 2021-06-15. The $MFT entry number is 12345. What is the most accurate conclusion regarding the timestamp manipulation?
31An analyst is creating a timeline from a forensic image of a Windows 7 system using The Sleuth Kit's fls and mactime tools. The analyst notices that the timeline includes entries for files that no longer exist on the volume. Which NTFS artifact is most likely responsible for these entries, and how should the analyst interpret them?
You must be able to build a MACB file system timeline and correctly interpret each timestamp's meaning and reliability. The most important thing is knowing which timestamps are trustworthy versus user-modifiable, and filtering super-timeline output before drawing conclusions.
The Courseiva GCFA question bank contains 31 questions in the Introduction to File System Timeline Forensics domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Introduction to File System Timeline Forensics domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included