Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

An analyst is creating a timeline from a forensic image of a Windows 7 system using The Sleuth Kit's fls and mactime tools. The analyst notices that the timeline includes entries for files that no longer exist on the volume. Which NTFS artifact is most likely responsible for these entries, and how should the analyst interpret them?

⚠ Common exam trap

The trap here is assuming that deleted files cannot appear in a timeline generated by fls, when in fact unallocated MFT entries are parsed and can produce such entries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The $MFT contains entries for deleted files that have not been overwritten, and these entries represent files that once existed and may still be recoverable.

The correct answer is the option describing the $MFT. NTFS keeps MFT records for deleted files in an unallocated state until they are reused. The Sleuth Kit's fls tool reads these records and includes them in the bodyfile, causing deleted files to appear in the timeline. Investigators should interpret such entries as evidence of past file existence and potential recoverable data. The $MFT is a primary source for file system timeline reconstruction, especially for files that have been deleted but not overwritten.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The $LogFile contains records of file system transactions, and it retains entries for files that were deleted, which the tool interprets as current files.

    Why it's wrong here

    This is incorrect because the $LogFile is a metadata journal used for crash recovery, not a source of deleted file entries for timeline creation. While it can contain records of file operations, it does not store full file names or timestamps in a way that would cause fls to list deleted files as if they were present. The $LogFile is typically parsed with specialized tools like LogFileParser, not by fls, and it does not persist indefinitely. Therefore, it is not the artifact responsible for the deleted file entries in the timeline.

  • ✗

    The $UsnJrnl records all changes to files, including deletions, and it retains the file names and timestamps for deleted files indefinitely.

    Why it's wrong here

    This is incorrect because the $UsnJrnl (Update Sequence Number Journal) does record file changes and deletions, but it does not retain entries indefinitely; it is a sparse file that is overwritten as new records are added. Moreover, The Sleuth Kit's fls tool does not parse the $UsnJrnl to generate bodyfile entries. While the $UsnJrnl is a valuable forensic artifact for timeline analysis, it is not the reason fls would list deleted files. The $UsnJrnl must be parsed separately, and its records do not persist forever, so it cannot be the source of the observed entries.

  • ✓

    The $MFT contains entries for deleted files that have not been overwritten, and these entries represent files that once existed and may still be recoverable.

    Why this is correct

    This is correct because the $MFT retains entries for deleted files until they are overwritten. When a file is deleted, its MFT record is marked as unallocated, but the record content, including timestamps and file name, often remains intact. The Sleuth Kit's fls tool can parse these unallocated entries and include them in the bodyfile, resulting in timeline entries for files that no longer exist. These entries are valuable because they indicate past file presence and can be used to reconstruct historical activity, and the data may still be recoverable if the clusters have not been reused.

  • ✗

    The $Bitmap tracks cluster allocation, and it includes entries for files that were deleted but whose clusters have not been reallocated.

    Why it's wrong here

    This is incorrect because the $Bitmap is a metadata file that tracks which clusters are allocated or free. It does not contain file names or timestamps, and it does not store entries for individual files. While it can indicate whether clusters are free or allocated, it cannot produce timeline entries for deleted files. The $Bitmap is used to determine cluster allocation status, not to list files. Therefore, it is not the source of the deleted file entries observed in the timeline.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.