GCFA Practice Question: Introduction to File System Timeline Forensics
A forensic analyst is building a file system timeline from an NTFS volume and wants to ensure it includes reliable evidence of file creation and deletion events. Which two artifacts should the analyst prioritize to capture these events? (Choose two.)
⚠ Common exam trap
The trap here is overlooking unallocated $MFT entries, which can still contain timestamps for deleted files, or assuming the $LogFile is a primary timeline source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$MFT entries, including unallocated records
The $MFT, including unallocated entries, provides timestamps for files that existed or were deleted. The $UsnJrnl:$J logs file system changes with timestamps, capturing creation and deletion events. Together, they offer a robust foundation for a file system timeline, allowing analysts to correlate timestamps and change records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Volume Shadow Copy snapshots
Why it's wrong here
Volume Shadow Copies are point-in-time snapshots of the volume that can be used to compare file states over time. They are not a primary artifact for capturing individual file creation or deletion events in a timeline, as they require differential analysis and may not include all changes.
- ✓
$MFT entries, including unallocated records
Why this is correct
$MFT entries contain the $STANDARD_INFORMATION and $FILE_NAME attributes with creation, modification, access, and entry modification timestamps. Unallocated entries can preserve timestamps for deleted files until reused, making the $MFT essential for both creation and deletion timeline events.
- ✓
$UsnJrnl:$J change journal
Why this is correct
The USN change journal records file system changes such as creation, deletion, rename, and data overwrite. Each record includes a USN and timestamp, providing a sequential log of events. It is particularly useful for capturing deletion events and can supplement MFT timestamps for a more complete timeline.
- ✗
$LogFile transaction log
Why it's wrong here
The $LogFile is used for NTFS metadata recovery and contains transaction records that may reference MFT changes. However, it is not designed for timeline reconstruction and does not provide a straightforward chronological list of file creation or deletion events.
- ✗
$Bitmap allocation file
Why it's wrong here
The $Bitmap tracks cluster allocation status but does not contain timestamps or file names. While it can indicate free space that might contain deleted file data, it cannot provide creation or deletion times, so it is not a primary source for timeline events.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.