GCFA Practice Question: Introduction to File System Timeline Forensics
A forensic analyst is examining an NTFS volume and wants to identify potential timestomping. Which TWO artifacts should the analyst compare to detect inconsistencies in file timestamps? (Choose two.)
⚠ Common exam trap
The trap here is assuming that all NTFS metadata contains file timestamps, when only specific attributes like $STANDARD_INFORMATION and $FILE_NAME store them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$FILE_NAME timestamps
Timestomping often modifies $STANDARD_INFORMATION timestamps while leaving $FILE_NAME timestamps unchanged. Comparing these two sets can reveal inconsistencies that indicate manipulation. Other artifacts like VBR, $Bitmap, or MFT record headers do not contain comparable per-file timestamps, so they are not useful for this specific detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
$FILE_NAME timestamps
Why this is correct
$FILE_NAME timestamps are updated by the file system during filename operations and are not directly modifiable by user-mode APIs. They often retain original values even when $STANDARD_INFORMATION is altered. Comparing these with $STANDARD_INFORMATION can expose timestomping. In this scenario, they are a key artifact for detecting inconsistencies.
- ✗
Volume Boot Record (VBR) timestamps
Why it's wrong here
The Volume Boot Record contains file system metadata such as cluster size and volume serial number, but it does not store per-file timestamps. It is not relevant for detecting timestomping on individual files. Comparing VBR timestamps would not provide information about file modification or creation times, so it is an incorrect choice.
- ✗
$Bitmap timestamps
Why it's wrong here
$Bitmap is a metadata file that tracks cluster allocation, but it does not contain timestamps for file events. It records which clusters are in use, not when files were modified or created. It is not a source of timestamp information for detecting timestomping, making it an incorrect choice for this comparison.
- ✗
Master File Table (MFT) record header timestamps
Why it's wrong here
The MFT record header contains fields such as the record's allocated status and sequence number, but it does not store the four standard file timestamps. While the MFT record itself contains $STANDARD_INFORMATION and $FILE_NAME attributes, the header timestamps are not a separate artifact for comparison. This option is not a valid choice for detecting timestomping.
- ✓
$STANDARD_INFORMATION timestamps
Why this is correct
$STANDARD_INFORMATION timestamps are commonly targeted by timestomping tools because they are easily modified via user-mode APIs. Comparing these with other artifacts can reveal discrepancies. In this scenario, they are a primary source for detecting manipulation, as altered values may not match other system records. The analyst should include them in the comparison.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.