GCFA NTFS Artifact Analysis Practice Question
A forensic analyst is reviewing an NTFS volume from a Windows 10 workstation. The analyst finds an MFT entry whose $STANDARD_INFORMATION attribute contains four timestamps that are all set to a date three years in the past, but the corresponding $FILE_NAME attribute timestamps show dates within the past week. The file's content matches a recently created document. Which conclusion is most strongly supported by this artifact discrepancy?
⚠ Common exam trap
The trap here is assuming that any timestamp discrepancy between $STANDARD_INFORMATION and $FILE_NAME automatically proves timestomping, when legitimate operations such as file moves within a volume or certain backup restores can also produce differences.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The $STANDARD_INFORMATION timestamps were deliberately altered by a timestomping tool, while the $FILE_NAME timestamps reflect the actual file system activity.
The $STANDARD_INFORMATION attribute is the primary target of timestomping tools because it is what most user-facing interfaces display. The $FILE_NAME attribute, which is indexed in the directory entry, is often left unchanged by such tools. A large discrepancy where $STANDARD_INFORMATION is backdated but $FILE_NAME reflects recent activity is a classic indicator of deliberate timestamp manipulation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The $STANDARD_INFORMATION timestamps were deliberately altered by a timestomping tool, while the $FILE_NAME timestamps reflect the actual file system activity.
Why this is correct
Timestomping utilities commonly modify the $STANDARD_INFORMATION timestamps because that is what Windows Explorer and many tools display, but they often overlook the $FILE_NAME attribute timestamps, which are updated by the file system during rename or creation events. The three-year-old values in $STANDARD_INFORMATION versus recent $FILE_NAME values strongly indicate deliberate manipulation of the $STANDARD_INFORMATION timestamps.
- ✗
The file was copied from an external NTFS volume, which preserved the original $STANDARD_INFORMATION timestamps but updated the $FILE_NAME timestamps.
Why it's wrong here
Copying a file to a new NTFS volume typically updates the $STANDARD_INFORMATION timestamps to the copy time, not the other way around. A file moved within the same volume retains both sets, while a copy generally refreshes the creation time in $STANDARD_INFORMATION. This option misstates which attribute is preserved during a cross-volume copy and does not fit the observed pattern.
- ✗
The volume was formatted with a non-default cluster size, which causes $STANDARD_INFORMATION and $FILE_NAME timestamps to be updated independently.
Why it's wrong here
Cluster size affects allocation and slack space, not timestamp update semantics. NTFS updates both $STANDARD_INFORMATION and $FILE_NAME timestamps according to defined file operations regardless of cluster size. A non-default cluster size would not cause a three-year gap between the two attribute timestamp sets for a recently created document.
- ✗
The file system journal was replayed after an unclean shutdown, causing the $STANDARD_INFORMATION timestamps to roll back while the $FILE_NAME timestamps were left intact.
Why it's wrong here
Journal replay restores metadata consistency but does not selectively roll back timestamps in $STANDARD_INFORMATION while leaving $FILE_NAME untouched. An unclean shutdown would not produce a coordinated three-year-old timestamp set in one attribute and recent timestamps in the other. This explanation invents a behavior that NTFS journaling does not perform.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.