20+ practice questions focused on File System Timeline Artifact Analysis — one of the most tested topics on the GIAC Certified Forensic Analyst exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start File System Timeline Artifact Analysis PracticeAn analyst is investigating an NTFS volume and notices that a file's $STANDARD_INFORMATION attribute modified timestamp is significantly earlier than its $FILE_NAME attribute modified timestamp. What is the most likely cause of this discrepancy during a forensic examination?
Explanation: Timestamp discrepancies between $STANDARD_INFORMATION and $FILE_NAME frequently occur when a file is copied or moved within the same NTFS volume. The copy operation creates new metadata where the $FILE_NAME is updated to the current time, while the $STANDARD_INFORMATION may retain copied or modified values depending on the specific user-space tool utilized.
An analyst is investigating a suspected malware execution. They notice the MFT entry for 'svchost.exe' shows a file creation time that is earlier than the MFT record modification time. Which artifact-based technique should the analyst employ to determine if a timestomp occurred?
Explanation: Comparing standard information (SI) attributes with file name (FN) attributes is critical in NTFS forensics. When a file is moved or copied, the FN attribute reflects the original creation time, whereas the SI attribute is easily manipulated by user-mode APIs. Discrepancies between these two timestamps are a hallmark indicator of timestomping. This matters because attackers frequently modify metadata to hide their activities within the file system hierarchy, requiring analysts to cross-reference multiple MFT attributes for integrity validation.
Which TWO of the following artifacts provide the most reliable evidence for reconstructing file system access history during a timeline analysis?
Explanation: The Shell Items (LNK files) and the USN Journal are essential because they capture specific events rather than just static metadata. LNK files track user interaction and file paths, while the USN Journal provides a chronological log of file system changes. Relying on these prevents reliance on malleable metadata that attackers often exploit. Accurate timeline reconstruction requires correlation between user activity and underlying file system changes to prove specific malicious actions occurred.
Refer to the exhibit. Based on the provided MFT attributes, what is the most likely conclusion regarding this file?
Explanation: The exhibit shows a scenario where the SI creation time is earlier than the FN creation time. In standard Windows file operations, the FN attribute should be identical to or older than the SI attribute because FN is created during the file's birth. If SI is older than FN, it implies that the SI attribute was likely manually modified by an attacker, effectively 'timestomping' the file to predate its actual existence on the disk.
When conducting a timeline analysis, which artifact is considered the most reliable source for determining when a file was actually deleted from an NTFS volume?
Explanation: The $LogFile and the $UsnJrnl are the primary sources for deletion events. While the MFT entry itself might be marked as free, the journal records contain transaction history that explicitly logs the deletion operation. Identifying the exact moment of deletion is critical for establishing a temporal boundary for attacker activities and determining what files were present during a specific window of time.
+15 more File System Timeline Artifact Analysis questions available
Practice all File System Timeline Artifact Analysis questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of File System Timeline Artifact Analysis. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
File System Timeline Artifact Analysis questions on the GCFA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. File System Timeline Artifact Analysis is tested as part of the GIAC Certified Forensic Analyst blueprint. Practicing with targeted File System Timeline Artifact Analysis questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCFA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but File System Timeline Artifact Analysis is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full File System Timeline Artifact Analysis practice session with instant scoring and detailed explanations.
Start File System Timeline Artifact Analysis Practice →