Be able to map a rename or deletion to the correct NTFS artifact and justify it with reason codes and timestamps. The single most important thing: know when to trust $UsnJrnl versus $LogFile versus $MFT metadata, and never rely on one timestamp alone.
Start practicing
NTFS Artifact Analysis — choose a session length
Free · No account required
Domain overview
This domain covers how NTFS stores metadata and change history across $MFT, $STANDARD_INFORMATION, $FILE_NAME, $LogFile, and $UsnJrnl. GCFA questions present imaging or live-response scenarios and ask you to identify which artifact proves a rename, creation, deletion, or timestamp inconsistency, and to reason about record ordering and journal retention.
Exam objectives
Interpreting $STANDARD_INFORMATION versus $FILE_NAME timestamp pairs in $MFT records
Using $UsnJrnl reason codes to prove file rename, creation, and deletion events
Distinguishing $LogFile transactional metadata from $UsnJrnl long-term change records
Correlating MFT record numbers, sequence numbers, and out-of-order profile folders
Assuming $STANDARD_INFORMATION timestamps are authoritative; $FILE_NAME timestamps often preserve earlier creation times and can reveal timestomping.
Treating $UsnJrnl as permanent; it is sparse and can be overwritten or deleted, so absence of records is not proof of no activity.
Confusing $LogFile with $UsnJrnl; $LogFile is a circular transaction log for crash recovery, not a long-term user activity journal.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An analyst discovers a file with a non-zero size but no data in the $DATA attribute. Where is the file content likely located?
2Which NTFS metadata file serves as the index for all files and directories on the volume?
3What is the primary function of the $ATTRIBUTE_LIST attribute in an MFT entry?
4What is the primary advantage of the $UsnJrnl over the $LogFile for long-term forensic analysis?
5What is the primary role of the $MFTMirr file in NTFS?
6What does a non-resident $DATA attribute indicate in an NTFS MFT record?
7What is the primary purpose of the $LogFile in NTFS?
8Which NTFS metadata attribute is responsible for storing Security Descriptors (ACLs)?
9Which NTFS master file table (MFT) record contains metadata about the MFT itself?
10During a forensic analysis, you encounter a file with a 'resident' $DATA attribute. What does this mean for your data recovery process?
11An analyst is examining the USN Journal. What is the primary purpose of this file in the context of NTFS forensic analysis?
12Which attribute is used to store the location and length of file data runs in an NTFS MFT record?
13What is the consequence of a file name being stored in the $FILE_NAME attribute but not in the $INDEX_ROOT of its parent directory?
14What is the significance of the $LogFile in NTFS when performing an investigation on a system that experienced a sudden power loss?
15Which NTFS attribute would an investigator primarily examine to determine the parent directory of a specific file?
16An examiner images a Windows 10 workstation and notices that several user profile folders are out of order in the \$MFT when sorted by MFT record number, yet the $STANDARD_INFORMATION timestamps are consistent. The examiner suspects that entries were reordered or that records were freed and reused. Which NTFS artifact best supports determining whether MFT record numbers have been reassigned to different files over time?
17A forensic analyst is reviewing a Windows 10 workstation suspected of unauthorized data staging. While parsing the Master File Table with a commercial forensic suite, the analyst observes that a suspicious .zip file's $STANDARD_INFORMATION timestamps differ from its $FILE_NAME timestamps by more than six months, and the $FILE_NAME timestamps are older. Which conclusion is most consistent with this artifact pattern?
18An analyst is examining an NTFS volume from a Windows Server 2019 system that was used as a file server. A file critical to the investigation is missing from the directory listing, but the analyst suspects the file was recently deleted and its MFT entry has not been overwritten. Which NTFS artifact should the analyst examine to recover the file's full path and name if the MFT entry is still intact?
19An investigator is analyzing an NTFS volume from a compromised server. A file named 'payroll.xlsx' appears in the directory listing, but the MFT record for that filename shows a zero-length $DATA attribute and no $OBJECT_ID. A separate MFT record with a different record number contains the same $FILE_NAME value, a large non-resident $DATA attribute, and an $OBJECT_ID. Which NTFS artifact best explains the presence of two MFT records referencing the same filename?
20During an investigation, you recover a deleted file from an NTFS volume. The MFT entry for the file shows that the $DATA attribute is non-resident, and the data runs are still intact. However, the $BITMAP attribute of the MFT indicates that the MFT entry is marked as unallocated. What is the most accurate conclusion about the recoverability of the file's content?
21A first responder is collecting volatile and non-volatile data from a running Windows Server 2019 system. The investigator needs to determine which user or process most recently renamed a specific file on an NTFS volume, but the $STANDARD_INFORMATION timestamps show only a modification time. Which NTFS artifact should the investigator query to find rename events that record the previous filename?
22You are analyzing an NTFS volume and need to determine the original path and name of a file that has been moved to a different directory. The file's MFT entry contains multiple $FILE_NAME attributes. Which two of the following statements about $FILE_NAME attributes are correct? (Choose two.)
23A forensic analyst is reviewing an NTFS volume from a Windows 10 workstation. The analyst finds an MFT entry whose $STANDARD_INFORMATION attribute contains four timestamps that are all set to a date three years in the past, but the corresponding $FILE_NAME attribute timestamps show dates within the past week. The file's content matches a recently created document. Which conclusion is most strongly supported by this artifact discrepancy?
24An investigator is analyzing an NTFS volume and finds that a file's $DATA attribute is non-resident and its data runs point to clusters that are currently allocated to a different file. The file's size is 10 KB. What is the most likely explanation for this situation?
25A forensic analyst is examining an NTFS volume and needs to identify which artifacts can provide evidence of file deletion or file system changes that occurred after a file was removed. Which TWO of the following NTFS artifacts are most directly useful for this purpose? (Choose two.)
26An investigator is examining an NTFS volume from a system that was abruptly powered off during a malware installation. The analyst observes that the MFT contains a file record for a suspicious executable with a valid $DATA attribute, but the file is not visible in the directory index. Which NTFS artifact should the analyst examine to determine whether the file record was orphaned due to an interrupted transaction?
27A forensic analyst is examining an NTFS volume and needs to determine whether a specific file was recently deleted and whether its data clusters have been reallocated. The analyst has access to the MFT, the $Bitmap metadata file, and the $UsnJrnl. Which two artifacts should the analyst correlate to confirm that the file's MFT record is unallocated and that its clusters are now marked as free? (Choose two.)
28An analyst is examining an NTFS volume and finds that a file's $DATA attribute is non-resident, but the file size reported by the operating system is 0 bytes. The analyst suspects the file may have been involved in a data hiding technique. Which of the following is the most likely explanation for this discrepancy?
29An analyst is examining an NTFS volume and finds a file named 'confidential.docx' in a directory. The file's MFT record shows that the $DATA attribute is resident. What does this indicate about the file's data storage, and what is the primary forensic implication?
30A forensic analyst is reviewing an NTFS volume and notices that a particular file has an $ATTRIBUTE_LIST attribute in its MFT record. What does the presence of this attribute indicate about the file?
31A forensic analyst is investigating a system where a user is suspected of using a tool to hide files by manipulating NTFS metadata. The analyst finds an MFT entry with a $FILE_NAME attribute that has a namespace value of 2 (POSIX) and a $STANDARD_INFORMATION attribute with timestamps that are inconsistent with the file's $UsnJrnl records. Which conclusion is most appropriate regarding the file's naming and timestamp artifacts?
32An analyst is examining an NTFS volume and finds that a file's $DATA attribute is resident. The file size is 800 bytes. The analyst attempts to recover the file content using a tool that only reads the data runs from the MFT record. What will be the outcome of this recovery attempt?
33An analyst is examining a Windows 10 system where a user deleted several files containing sensitive data. The analyst needs to recover the file content and determines that the $DATA attribute of the MFT record for one deleted file is resident. What does this indicate about the file's data and its recoverability?
34An examiner is analyzing an NTFS volume from a Windows Server 2016 system that was abruptly powered off during a security incident. The examiner wants to determine recent file system changes that may not have been flushed to the $MFT. Which two NTFS artifacts should the examiner prioritize to reconstruct recent metadata operations? (Choose two.)
35An analyst is examining an NTFS volume and wants to identify the MFT entry for a specific file named 'report.docx'. The analyst knows the file's path but needs to locate its MFT record number to examine its attributes. Which NTFS metadata file should the analyst consult to map the file path to its MFT record number?
36A forensic analyst is examining an NTFS volume and finds that a directory's $I30 index entries are present in the $INDEX_ROOT, but the $INDEX_ALLOCATION attribute is non-resident and points to INDX records. The analyst needs to determine whether a deleted file once existed in that directory. Which artifact should the analyst examine to find residual filename entries that may reference the deleted file?
37A forensic analyst is reviewing an NTFS volume and notices that a particular MFT record has an $ATTRIBUTE_LIST attribute. The analyst wants to understand why this attribute is present. Which of the following best describes the purpose of the $ATTRIBUTE_LIST attribute in an MFT record?
Be able to map a rename or deletion to the correct NTFS artifact and justify it with reason codes and timestamps. The single most important thing: know when to trust $UsnJrnl versus $LogFile versus $MFT metadata, and never rely on one timestamp alone.
The Courseiva GCFA question bank contains 37 questions in the NTFS Artifact Analysis domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the NTFS Artifact Analysis domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included