GCFA Introduction to File System Timeline Forensics • Set 2
GCFA Introduction to File System Timeline Forensics Practice Test 2 — 15 questions with explanations. Free, no signup.
A forensic analyst is examining a Windows 10 system and wants to build a comprehensive file system timeline. The analyst has already parsed the $MFT and USN journal. Which TWO additional artifacts should the analyst incorporate to most effectively correlate file system events with user and system activity? (Choose two.)
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.