20+ practice questions focused on NTFS Artifact Analysis — one of the most tested topics on the GIAC Certified Forensic Analyst exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start NTFS Artifact Analysis PracticeWhich TWO of the following MFT attributes are most relevant for detecting timestomping activity?
Explanation: The $STANDARD_INFORMATION and $FILE_NAME attributes are the two primary locations where NTFS stores timestamps. Malware often modifies the $STANDARD_INFORMATION attribute to deceive forensic tools, but it frequently fails to update the $FILE_NAME attribute because the operating system manages it differently. Comparing these two sets of timestamps allows an analyst to identify discrepancies that indicate malicious manipulation of file metadata during an incident response investigation.
Which THREE of the following are valid components of an NTFS MFT record?
Explanation: Every NTFS MFT record consists of a header, an attribute list, and the attributes themselves. The header contains metadata about the record, while the attributes (like $STANDARD_INFORMATION, $FILE_NAME, and $DATA) hold the actual file information. Mastering these structural components is essential for manual MFT parsing, which is often required when forensic tools fail to interpret corrupted entries or hidden data streams.
Which NTFS attribute would an investigator examine to recover a deleted file's original name if the $MFT entry was partially overwritten?
Explanation: The $FILE_NAME attribute is stored in the MFT record and is often preserved even when a file is deleted. Since the operating system manages this attribute strictly, it is a highly reliable source for identifying files, especially when the $STANDARD_INFORMATION attribute has been modified. Even if the primary record is damaged, checking for multiple $FILE_NAME entries or parsing the MFT can often yield the original file name.
Which THREE items are included in the $STANDARD_INFORMATION attribute?
Explanation: The $STANDARD_INFORMATION attribute is the primary source for the MACE timestamps that forensic analysts rely on for timeline reconstruction. It also contains the file's security ID and attributes like 'read-only' or 'hidden'. While these timestamps are easily modified by user-level tools, they remain a critical starting point for any forensic timeline, providing the baseline for comparison against the more robust $FILE_NAME attribute timestamps.
An analyst is investigating a suspicious file and identifies that the filename is stored in the $FILE_NAME attribute but not in the $DATA attribute. What does this indicate regarding the file's state?
Explanation: In NTFS, the $FILE_NAME attribute is managed by the kernel and remains static, while the $DATA attribute represents the actual file content. When a file is deleted, the entry in the Master File Table (MFT) is marked as free, and the $DATA attribute is often zeroed or deallocated. Identifying a mismatch or missing data indicates the file was likely deleted, emphasizing the importance of MFT analysis for recovery.
+15 more NTFS Artifact Analysis questions available
Practice all NTFS Artifact Analysis questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of NTFS Artifact Analysis. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
NTFS Artifact Analysis questions on the GCFA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. NTFS Artifact Analysis is tested as part of the GIAC Certified Forensic Analyst blueprint. Practicing with targeted NTFS Artifact Analysis questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCFA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but NTFS Artifact Analysis is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full NTFS Artifact Analysis practice session with instant scoring and detailed explanations.
Start NTFS Artifact Analysis Practice →