Courseiva
NTFS Artifact Analysis →mediumMultiple Select

GCFA NTFS Artifact Analysis Practice Question

A forensic analyst is examining an NTFS volume and needs to identify which artifacts can provide evidence of file deletion or file system changes that occurred after a file was removed. Which TWO of the following NTFS artifacts are most directly useful for this purpose? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse general NTFS metadata files with event-logging artifacts, when only $Bitmap and the USN journal provide direct evidence of deletion and post-deletion changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$UsnJrnl:$J, which logs file system events including FILE_DELETE and CLOSE reasons.

$Bitmap tracks cluster allocation and can show clusters freed by deletion, while $UsnJrnl:$J logs file system events including FILE_DELETE with timestamps and file references. Together they help identify deleted files and the timing of deletions, making them the most directly useful artifacts among the listed metadata files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    $UsnJrnl:$J, which logs file system events including FILE_DELETE and CLOSE reasons.

    Why this is correct

    The USN change journal records events with reason flags, including FILE_DELETE, which indicates a file was deleted. Each record includes the file reference number and timestamp, allowing analysts to correlate deletion events with other activity. This directly supports determining when and possibly how a file was removed.

  • ✗

    $Volume, which contains the volume label and version information and can indicate volume format changes.

    Why it's wrong here

    $Volume stores the volume label, NTFS version, and dirty flag. It does not log file-level events or deletions. While the dirty flag can indicate an unclean shutdown, it does not provide evidence of specific file deletions or changes after a file was removed.

  • ✓

    $Bitmap, which tracks cluster allocation and can show clusters freed after a file deletion.

    Why this is correct

    $Bitmap is a metadata file where each bit represents a cluster's allocation state. When a file is deleted, its clusters are deallocated and the corresponding bits are cleared. Analyzing $Bitmap can reveal which clusters were freed, helping to identify areas of the disk that may contain recoverable file content from deleted files.

  • ✗

    $AttrDef, which defines valid attribute types and can show when new attributes were added.

    Why it's wrong here

    $AttrDef is a metadata file that lists attribute definitions, such as type codes and collation rules, used by NTFS. It is static and does not record per-file events or deletions. Changes to $AttrDef are rare and unrelated to routine file deletion activity on the volume.

  • ✗

    $Boot, which stores the volume boot sector and can indicate when the volume was last mounted.

    Why it's wrong here

    $Boot contains the boot sector, including the OEM ID, bytes per sector, clusters per file record, and the MFT starting cluster. It does not track file deletions or cluster allocation changes; while it can be used to interpret volume geometry, it offers no direct evidence of post-deletion file system activity.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.