GCFA › Introduction to File System Timeline Forensics
This domain covers building and interpreting file system timelines for forensics, focusing on NTFS and ext4 metadata, MACB timestamp semantics, and tools like log2timeline, Plaso, and The Sleuth Kit. Questions test whether you can extract, filter, and reason about timestamps rather than merely generate a timeline.
GCFA Introduction to File System Timeline Forensics — All 59 Questions
Every question in this domain with answers and detailed explanations.