Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

A forensic analyst is building a timeline from an NTFS volume and wants to include the time when a file's metadata was last changed, such as permission modifications. Which timestamp should the analyst focus on to capture this event?

⚠ Common exam trap

It's easy for candidates to confuse the entry modified time (ctime) with the creation time (crtime) or assuming that mtime captures all changes, when in fact ctime specifically records metadata changes like permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entry modified time (ctime)

In NTFS, the entry modified time (ctime) is updated whenever the file's MFT record is changed, which includes modifications to security descriptors, ownership, and other metadata. This makes it the correct timestamp for detecting permission changes. The modified time (mtime) only reflects data writes, the accessed time (atime) reflects reads, and the creation time (crtime) is fixed at file creation. Thus, ctime is the key timestamp for metadata alterations such as permission modifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accessed time (atime)

    Why it's wrong here

    The accessed time (atime) indicates when the file was last read or executed. It is not updated when metadata such as permissions are changed. In fact, atime updates can be disabled or delayed on many systems, making it unreliable for tracking metadata changes. Permission modifications do not trigger an atime update, so this timestamp would not capture the event.

  • ✓

    Entry modified time (ctime)

    Why this is correct

    The entry modified time (ctime) in NTFS, also known as the MFT change time, is updated whenever the file's metadata or MFT record changes, including permission modifications, ownership changes, or attribute updates. It does not change when only file content is modified (that updates mtime). Thus, ctime is the correct timestamp to capture metadata changes like permission alterations.

  • ✗

    Modified time (mtime)

    Why it's wrong here

    The modified time (mtime) records when the file's data content was last written to. It does not track changes to metadata such as permissions or ownership. In NTFS, mtime is updated when the file's contents change, not when attributes like security descriptors are altered. Therefore, relying on mtime would miss permission changes that do not affect file data.

  • ✗

    Creation time (crtime)

    Why it's wrong here

    Creation time (crtime) records when the file was first created on the volume. It is set once at creation and does not change when permissions or other metadata are modified later. While crtime is useful for establishing when a file appeared, it cannot indicate subsequent permission changes. Therefore, it is not the appropriate timestamp for tracking metadata modifications.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.