Courseiva
NTFS Artifact Analysis →mediumMultiple Select

GCFA NTFS Artifact Analysis Practice Question

A forensic analyst is examining an NTFS volume and needs to determine whether a specific file was recently deleted and whether its data clusters have been reallocated. The analyst has access to the MFT, the $Bitmap metadata file, and the $UsnJrnl. Which two artifacts should the analyst correlate to confirm that the file's MFT record is unallocated and that its clusters are now marked as free? (Choose two.)

⚠ Common exam trap

The trap here is assuming that the $UsnJrnl or $LogFile can confirm cluster reallocation, when only the $Bitmap tracks current cluster allocation status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The in-use flag in the file's MFT record header, which indicates whether the record is allocated or unallocated.

To confirm that a file's MFT record is unallocated and its clusters are free, the analyst should check the in-use flag in the MFT record header and the corresponding bits in the $Bitmap file. The in-use flag directly indicates whether the record is allocated, while the $Bitmap tracks cluster allocation across the volume. Together they provide definitive evidence of deletion and cluster reallocation status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The in-use flag in the file's MFT record header, which indicates whether the record is allocated or unallocated.

    Why this is correct

    The MFT record header contains an in-use flag that NTFS sets to 0 when a file is deleted, marking the record as unallocated. This is a primary indicator that the file no longer exists in the active file system. The analyst can parse this flag directly from the MFT record to confirm the file's deletion state, independent of other metadata.

  • ✓

    The $Bitmap metadata file, which tracks the allocation status of clusters on the volume.

    Why this is correct

    The $Bitmap file contains a bit for each cluster on the volume, where 0 indicates a free cluster and 1 indicates an allocated cluster. By examining the bits corresponding to the clusters previously used by the deleted file, the analyst can determine whether those clusters have been reallocated or remain free. This directly answers whether the file's data clusters are now marked as free.

  • ✗

    The $Secure metadata file, which contains security descriptors and can indicate whether the file was protected from deletion.

    Why it's wrong here

    The $Secure file stores security descriptors for files and directories, not allocation status or deletion state. It does not track whether a file's MFT record is allocated or whether its clusters are free. Security descriptors are irrelevant to determining cluster reallocation after deletion, so this artifact does not help answer the analyst's question.

  • ✗

    The $LogFile, which records all metadata transactions and can show the exact deletion operation.

    Why it's wrong here

    The $LogFile records metadata transactions for crash recovery, but it is a circular log that may have been overwritten since the deletion. While it can show deletion operations if the relevant log records are still present, it does not directly indicate whether the file's clusters are currently free. The question asks for confirmation of cluster reallocation, which $LogFile does not provide.

  • ✗

    The $UsnJrnl, which records file system changes including deletions and can provide a timestamp for the deletion event.

    Why it's wrong here

    The $UsnJrnl records change journal entries, including deletion events, and can provide a timestamp for when the deletion occurred. However, it does not track cluster allocation status. While useful for establishing the deletion timeline, it does not confirm whether the file's clusters have been reallocated or remain free, which is the second part of the analyst's requirement.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.