GCFA Identification of Malicious and Normal Activity • Set 2
GCFA Identification of Malicious and Normal Activity Practice Test 2 — 15 questions with explanations. Free, no signup.
During a forensic investigation of a Windows 10 workstation, an analyst examines the $MFT and discovers that the file record for a suspicious executable shows a Standard Information Attribute (SIA) creation timestamp that is later than its Filename Attribute (FNA) creation timestamp. The executable resides in C:\Windows\Temp. Which of the following best explains this discrepancy and its forensic significance?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.