GCFA • Practice Test 19
Free GCFA practice test — 15 questions with explanations. Set 19. No signup required.
An analyst acquires a forensic image of a Windows 10 NTFS volume using a write blocker and now needs to build a file system timeline. The analyst wants to include the $STANDARD_INFORMATION timestamps but also wants to detect timestomping by comparing them with the $FILE_NAME timestamps. Which tool should the analyst use to extract both timestamp sets from the MFT and generate a bodyfile for timeline creation?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.