Courseiva
NTFS Artifact Analysis →hardMultiple Choice

GCFA NTFS Artifact Analysis Practice Question

A forensic analyst is investigating a system where a user is suspected of using a tool to hide files by manipulating NTFS metadata. The analyst finds an MFT entry with a $FILE_NAME attribute that has a namespace value of 2 (POSIX) and a $STANDARD_INFORMATION attribute with timestamps that are inconsistent with the file's $UsnJrnl records. Which conclusion is most appropriate regarding the file's naming and timestamp artifacts?

⚠ Common exam trap

The trap here is assuming that a POSIX namespace always indicates a benign POSIX application, when it can also be used to create hidden or hard-to-access files on Windows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The POSIX namespace suggests the file name contains characters that are not allowed in the Win32 namespace, and the timestamp inconsistency may indicate the file was moved or its timestamps were altered.

The POSIX namespace in NTFS is used for file names that are valid in POSIX but not in the Win32 namespace, such as those ending with a space or period. Attackers can use such names to hide files from typical Windows tools. The inconsistency between $STANDARD_INFORMATION timestamps and $UsnJrnl records suggests the $STANDARD_INFORMATION timestamps may have been manipulated, a common anti-forensic technique. Analysts should correlate these artifacts to detect hidden or altered files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The POSIX namespace indicates the file was created by a POSIX-compliant application, and the timestamp inconsistency is likely due to time zone differences.

    Why it's wrong here

    The POSIX namespace in NTFS is used for names that are compatible with POSIX conventions, such as case-sensitive names, but it does not indicate the creating application. Timestamp inconsistencies between $STANDARD_INFORMATION and $UsnJrnl are not explained by time zone differences, as both store UTC times. This option misinterprets the namespace and dismisses the inconsistency without valid cause.

  • ✗

    The POSIX namespace is used for files that are encrypted with EFS, and the timestamp inconsistency indicates the file was recently decrypted.

    Why it's wrong here

    The POSIX namespace is unrelated to EFS encryption. EFS-encrypted files are marked by the $EFS attribute and encrypted file system flags, not by the POSIX namespace. Timestamp inconsistencies do not indicate decryption. This option incorrectly associates the POSIX namespace with encryption and misinterprets the timestamp evidence.

  • ✓

    The POSIX namespace suggests the file name contains characters that are not allowed in the Win32 namespace, and the timestamp inconsistency may indicate the file was moved or its timestamps were altered.

    Why this is correct

    The POSIX namespace is used when a file name contains characters that are valid in POSIX but not in Win32, such as trailing spaces or periods. Such names can be used to hide files. The timestamp inconsistency between $STANDARD_INFORMATION and $UsnJrnl records suggests that the $STANDARD_INFORMATION timestamps may have been altered after the file's creation or last change, which is a common anti-forensic technique.

  • ✗

    The POSIX namespace indicates the file is a hard link, and the timestamp inconsistency is due to the link being created at a different time than the original file.

    Why it's wrong here

    Hard links are represented by multiple $FILE_NAME attributes, but the namespace value does not indicate a hard link. A file with a POSIX namespace name simply has a name that follows POSIX rules. Timestamp inconsistencies between $STANDARD_INFORMATION and $UsnJrnl are not explained by hard link creation, as hard links share the same $STANDARD_INFORMATION.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.