Be able to locate and interpret NTFS metadata, registry execution artifacts, and Jump Lists on a Windows image. The most important thing is distinguishing evidence of file presence from evidence of actual execution, and knowing which timestamps and artifacts can be trusted.
Start practicing
Windows Artifact Analysis — choose a session length
Free · No account required
Domain overview
This domain covers forensic examination of NTFS metadata, registry-backed execution artifacts, and shell item databases on Windows hosts. GCFA tests whether you can interpret $MFT records, $STANDARD_INFORMATION versus $FILE_NAME timestamps, ShimCache/AmCache entries, UserAssist, and Jump Lists to reconstruct file creation, execution, and user activity from an acquired image.
Exam objectives
Interpreting $MFT record attributes, resident vs non-resident data, and $STANDARD_INFORMATION versus $FILE_NAME timestamps
Using ShimCache (AppCompatCache) and AmCache to infer executable presence versus confirmed execution
Parsing Jump Lists in AutomaticDestinations and CustomDestinations, including .automaticDestinations-ms OLE structure
Examining NTFS attributes such as hidden, system, and alternate data streams used to conceal files
Treating a ShimCache entry as proof of execution; it only shows the file was seen by the system, not necessarily run.
Assuming $STANDARD_INFORMATION timestamps are reliable; they are easily modified, unlike $FILE_NAME timestamps.
Confusing Jump List folders or extensions, such as mixing AutomaticDestinations with CustomDestinations or wrong file suffixes.
Click any question to see the full explanation and answer options, or start a focused practice session above.
When analyzing the 'TypedPaths' registry key, what type of user activity is being reviewed?
2An analyst discovers a file on a system that appears to be a 'hidden' executable. Which attribute of the NTFS file system, if modified, is a common indicator of a user attempting to conceal a file from standard Explorer views?
3Which artifact is the most reliable for determining if an external USB mass storage device was mounted on a system, even if the device is no longer present?
4Which registry hive contains the 'UserAssist' key, and what is its primary forensic value?
5An analyst discovers a suspicious executable in the C:\Users\Public folder. To determine if the file was executed, the analyst examines the Shimcache. Which behavior is characteristic of the Shimcache artifact?
6An investigator is analyzing the Windows Event Logs and finds Event ID 4697. What is the primary significance of this event in the context of forensic analysis?
7When reviewing Jump Lists on a Windows system, which file extension is commonly associated with the 'AutomaticDestinations' folder?
8What is the primary function of the ShellBags artifact in a Windows forensic investigation?
9When analyzing the Windows Registry, what is the primary purpose of the 'SAM' hive?
10Which of the following describes the correct function of the $MFT (Master File Table) in an NTFS-formatted Windows volume?
11During an intrusion investigation, an analyst needs to determine the exact moment a malicious service was installed on a Windows 10 host. The attacker deleted the service's executable and cleared the System event log. Which artifact should the analyst examine to recover the service installation timestamp?
12During a compromise investigation, an analyst reviews Windows Event Logs and observes that Security Event ID 4688 entries are present, but the Process Command Line field is empty for all of them. The system is running Windows 10 Enterprise. What is the most likely reason for the missing command line data?
13An analyst is examining a Windows 10 workstation that is suspected of having a malicious service installed for persistence. The analyst wants to determine the original path of the service executable and the account it runs under. Which registry location should the analyst examine to find this information?
14During a forensic examination of a Windows 10 workstation, an analyst needs to determine which user account was interactively logged on at a specific date and time. The system is powered off and only the disk image is available. Which artifact should the analyst examine to find the most reliable record of interactive logon sessions, including logon type and timestamp?
15An analyst is reviewing a Windows 10 endpoint and finds that a scheduled task was created to run a PowerShell script at logon. The task was likely created by an attacker to maintain persistence. Which artifact should the analyst examine to determine the exact time the task was registered and the user account that created it?
16An analyst is examining a Windows 10 host and finds that a suspicious process was launched shortly after a user logged on. To determine the exact time the process was created and capture its parent-child relationship, which artifact should the analyst prioritize?
17An investigator is analyzing a Windows 10 system where an attacker allegedly used a PowerShell script to download and execute a malicious payload. The investigator wants to determine the exact PowerShell commands that were executed. Which Windows artifact should the investigator examine to find this information?
18A forensic analyst is examining a Windows 10 system and wants to determine which USB storage devices have been connected to the machine. The analyst has access to the registry. Which registry key should the analyst examine to find a list of USB devices that have been connected, including vendor and product IDs?
19An analyst is examining a Windows 10 system to determine if a specific USB device was connected. The analyst has already checked the registry and found no trace in USBSTOR. Which TWO additional artifacts should the analyst examine to corroborate USB device connection? (Choose two.)
20An analyst is investigating a Windows 10 system and discovers that a user's NTUSER.DAT registry hive contains a key named 'RecentDocs' with numerous entries. What is the primary forensic significance of this artifact?
21An analyst is reviewing a Windows 10 system and wants to determine the last time a user accessed a specific file. The analyst examines the file's NTFS standard information attributes and finds that the last access time is not updated. What is the most likely reason for this?
22An analyst is investigating a Windows 10 system and finds a suspicious shortcut file in a user's Recent folder. The analyst wants to determine the full path of the target file and any command-line arguments used when the shortcut was created. Which artifact should the analyst examine?
23An analyst is investigating a Windows 10 system for evidence of lateral movement. The analyst suspects that an attacker used PsExec to remotely execute commands on the system. Which TWO artifacts should the analyst examine to corroborate this activity? (Choose two.)
24An analyst is examining a Windows 10 system to determine if a specific user account was used to access files on a remote share. Which two artifacts would provide the most direct evidence of this activity? (Choose two.)
25An investigator is examining a Windows 10 system and finds a prefetch file named 'POWERSHELL.EXE-12345678.pf' in the C:\Windows\Prefetch folder. What is the primary forensic value of this artifact?
26An analyst is investigating a Windows 10 system where an attacker allegedly used a remote access tool (RAT) that persists by modifying the Image File Execution Options (IFEO) registry key. The analyst wants to identify which executable was hijacked. Which registry location should the analyst examine to find the Debugger value that redirects execution?
27An analyst is examining a Windows 10 system and finds a suspicious file in the Recycle Bin. The analyst wants to determine the original path of the file before it was deleted. Which artifact should the analyst examine to find the original file path and deletion time?
28An analyst is examining a Windows 10 system and finds that the ShimCache (AppCompatCache) contains an entry for a malicious executable. The analyst wants to determine whether the executable was actually executed on the system. Which additional artifact should the analyst examine to confirm execution?
Be able to locate and interpret NTFS metadata, registry execution artifacts, and Jump Lists on a Windows image. The most important thing is distinguishing evidence of file presence from evidence of actual execution, and knowing which timestamps and artifacts can be trusted.
The Courseiva GCFA question bank contains 28 questions in the Windows Artifact Analysis domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Windows Artifact Analysis domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included