GCFA NTFS Artifact Analysis Practice Question
A forensic analyst is reviewing an NTFS volume and notices that a particular file has an $ATTRIBUTE_LIST attribute in its MFT record. What does the presence of this attribute indicate about the file?
⚠ Common exam trap
Many candidates confuse $ATTRIBUTE_LIST with attributes that indicate specific features like encryption or compression, when it is actually a structural mechanism for managing attribute overflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file's attributes are spread across multiple MFT records because they do not fit in a single record.
The $ATTRIBUTE_LIST attribute is present when a file's attributes cannot fit in a single MFT record. It enumerates the attributes and their locations, which may be in additional MFT records. This is common for files with many attributes or large attributes like long $DATA runs or numerous alternate data streams. Its presence indicates that the file's metadata is distributed across multiple MFT records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file has multiple $DATA attributes, indicating alternate data streams.
Why it's wrong here
Alternate data streams are indicated by multiple $DATA attributes, but they do not necessarily require an $ATTRIBUTE_LIST. The $ATTRIBUTE_LIST is used when a file's attributes do not fit in a single MFT record, which can occur for various reasons, not just multiple data streams. The presence of an $ATTRIBUTE_LIST does not specifically indicate alternate data streams.
- ✗
The file is compressed, and the $ATTRIBUTE_LIST contains the compression unit size.
Why it's wrong here
Compression in NTFS is indicated by the $DATA attribute's flags (compressed bit) and the compression unit size is stored in the $DATA attribute, not in $ATTRIBUTE_LIST. The $ATTRIBUTE_LIST is not specific to compressed files; it is used whenever attributes do not fit in the base MFT record, regardless of compression.
- ✓
The file's attributes are spread across multiple MFT records because they do not fit in a single record.
Why this is correct
The $ATTRIBUTE_LIST attribute is used when a file's attributes exceed the space available in a single MFT record. It lists the attributes and their locations, which may be in additional MFT records. This allows NTFS to manage files with many attributes or large attributes that cannot be stored in one record. This is the primary purpose of the $ATTRIBUTE_LIST.
- ✗
The file is encrypted with EFS, and the $ATTRIBUTE_LIST stores encryption keys.
Why it's wrong here
EFS encryption is indicated by the $EFS attribute, not $ATTRIBUTE_LIST. The $ATTRIBUTE_LIST does not store encryption keys; it only lists attribute locations. EFS metadata is stored in the $EFS attribute, which may be listed in the $ATTRIBUTE_LIST if it does not fit in the base record, but the presence of $ATTRIBUTE_LIST alone does not indicate encryption.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.