Courseiva

GCFA File System Timeline Artifact Analysis Practice Question

A forensic analyst is creating a timeline from an NTFS volume and wants to include the $MFT's record number 0, which contains metadata about the MFT itself. What is the primary purpose of including this record in the timeline?

⚠ Common exam trap

Candidates often confuse the $MFT's own record with the $Volume metadata file, which does contain volume creation information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It contains the $MFT's own metadata timestamps, which can indicate when the MFT was last modified or extended, useful for detecting file system changes.

MFT record 0 is the $MFT's own file record, and its timestamps track changes to the MFT structure itself. Including it in a timeline helps analysts identify when the MFT was modified, which can correlate with mass file operations or anti-forensic activity. It does not provide volume creation, deleted file lists, or mount times.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It contains the $MFT's own metadata timestamps, which can indicate when the MFT was last modified or extended, useful for detecting file system changes.

    Why this is correct

    Record 0 is the $MFT's own file record. Its timestamps reflect changes to the MFT itself, such as when entries are added or removed, or when the MFT is extended. Including it in a timeline can help identify periods of significant file system activity or potential anti-forensic manipulation of the MFT.

  • ✗

    It stores the list of all deleted files, which can be used to recover evidence of file deletion.

    Why it's wrong here

    Record 0 does not store a list of deleted files. Deleted file records are found in unallocated MFT entries or in the $UsnJrnl. Record 0 is exclusively for the $MFT's own metadata. Its inclusion in a timeline does not directly aid in recovering deleted files.

  • ✗

    It provides the creation timestamp of the volume, which is essential for establishing the system's install date.

    Why it's wrong here

    Record 0 of the $MFT does not store the volume creation timestamp. The volume creation time is typically found in the $Volume metadata file. Record 0 contains the $MFT's own metadata, such as its size and allocation, not the volume's install date.

  • ✗

    It records the last time the volume was mounted, which is critical for correlating with external device connection times.

    Why it's wrong here

    The last mount time is not stored in MFT record 0. Volume mount information is typically found in the registry or in the $LogFile, not in the $MFT. Record 0's timestamps relate to the MFT's own structure, not volume mount events.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.