GCFA Windows Artifact Analysis Practice Question
An analyst discovers a file on a system that appears to be a 'hidden' executable. Which attribute of the NTFS file system, if modified, is a common indicator of a user attempting to conceal a file from standard Explorer views?
⚠ Common exam trap
Candidates often try to find the hidden file by searching for specific Registry keys, forgetting that the 'Hidden' attribute is a file-level metadata property stored within the MFT.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
File Attribute Flags (MFT)
NTFS file attributes allow users to hide files from the standard Windows Explorer interface. By checking the File Attributes field in the Master File Table (MFT), an analyst can identify files marked with the 'Hidden' or 'System' attribute. This is a common, albeit simple, anti-forensics technique used by adversaries to prevent casual discovery of malicious binaries or staged data, and it is the first step in identifying deliberate concealment attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
File Creation Timestamp
Why it's wrong here
The File Creation Timestamp is a temporal attribute, not a visibility attribute. While it can be timestomped to confuse an investigator, it does not determine whether a file is hidden from the user interface. Changing this timestamp will not make a file invisible in Windows Explorer.
- ✓
File Attribute Flags (MFT)
Why this is correct
The MFT stores the attributes for every file on an NTFS volume. The 'Hidden' attribute flag, when set, instructs the operating system to omit the file from standard folder views. Identifying this flag is essential for uncovering files that the attacker intentionally obscured from the user.
- ✗
Extended Attributes (EA)
Why it's wrong here
Extended Attributes are used for custom metadata and are not responsible for hiding files from the Windows Explorer interface. While they can be used to store malicious data, they are not the mechanism the OS uses to determine if a file should be visible to the user.
- ✗
Access Control List (ACL)
Why it's wrong here
An ACL manages user permissions for a file, determining who can read or execute it. An ACL does not hide a file from the interface; rather, it restricts access to it. Modifying permissions is a separate task from hiding a file and will not prevent a user from seeing the file.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.