Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

An analyst is building a file system timeline from an NTFS volume and is deciding which timestamps to extract from the $STANDARD_INFORMATION attribute. A colleague suggests that the four timestamps in $STANDARD_INFORMATION are the only relevant times. Which statement correctly describes the relationship between $STANDARD_INFORMATION and $FILE_NAME timestamps?

⚠ Common exam trap

The trap here is treating one attribute's timestamps as authoritative and ignoring the other, which discards corroborating or contradictory evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$STANDARD_INFORMATION and $FILE_NAME each contain four timestamps, and comparing them can reveal timestamp manipulation or file moves.

NTFS stores timestamps in both the $STANDARD_INFORMATION and $FILE_NAME attributes of an MFT record. The two sets are maintained by different mechanisms and can disagree, which is itself valuable evidence. An analyst should extract both and compare them rather than relying on a single source, because the discrepancies often indicate moves, renames, or deliberate timestamp alteration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    $STANDARD_INFORMATION timestamps are always more reliable than $FILE_NAME timestamps and should be used exclusively.

    Why it's wrong here

    Neither set is universally more reliable. $STANDARD_INFORMATION can be modified by user-mode APIs and even timestomping tools, while $FILE_NAME records are updated by the file system on specific operations. Using both and noting discrepancies gives the most accurate reconstruction.

  • ✗

    $FILE_NAME timestamps are only populated when a file is created and never change afterward.

    Why it's wrong here

    $FILE_NAME timestamps can be updated during operations such as renaming or moving a file within the same volume. They are not static after creation, so treating them as immutable would cause the analyst to miss evidence of later file activity on the timeline.

  • ✗

    $FILE_NAME timestamps are duplicates of $STANDARD_INFORMATION and can be ignored.

    Why it's wrong here

    The two attribute sets can diverge. $FILE_NAME timestamps are updated on certain operations such as file rename or move within the same volume, while $STANDARD_INFORMATION can be updated by other operations. Ignoring $FILE_NAME times discards evidence of rename or move activity that may be critical to the timeline.

  • ✓

    $STANDARD_INFORMATION and $FILE_NAME each contain four timestamps, and comparing them can reveal timestamp manipulation or file moves.

    Why this is correct

    Both attributes hold creation, modification, MFT change, and access times. Because they are updated by different code paths, discrepancies between them can indicate timestomping or a file move or rename, making both sets valuable for a defensible timeline.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.