GCFA File System Timeline Artifact Analysis Practice Question
An analyst is examining a file that was deleted. Why is the 'File Name' (FN) attribute in the MFT still potentially readable?
⚠ Common exam trap
Many candidates incorrectly believe that deleting a file immediately wipes the MFT record, leading them to assume that metadata for deleted files is irretrievable from the MFT itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTFS does not zero out MFT records upon deletion.
When a file is deleted in NTFS, the MFT record is marked as free, but the data within the record is not immediately wiped or zeroed. The FN attribute remains in the MFT entry until the record is reallocated to a new file. This is a critical forensic detail because it allows analysts to recover metadata from deleted files, often providing the only remaining evidence of a file's existence after the data clusters have been overwritten.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The MFT entry is locked by the OS kernel.
Why it's wrong here
The OS does not lock deleted MFT entries. The entry is marked as 'free' for the file system to reuse. The persistence of the data is due to the lack of an immediate wipe operation, not a locking mechanism, and the data remains accessible to forensic tools until an allocation occurs.
- ✓
NTFS does not zero out MFT records upon deletion.
Why this is correct
NTFS optimizes performance by simply marking MFT entries as available during deletion rather than zeroing out the data. This leaves the previous contents, including the FN attribute, intact in the record until a subsequent file creation operation overwrites it with new metadata, which is a core concept in forensic recovery.
- ✗
The file was stored on a compressed volume.
Why it's wrong here
Compression affects how file data is stored in the $DATA attribute, not how the MFT handles the lifecycle of an entry. The persistence of the FN attribute after deletion is a general NTFS characteristic, independent of whether the volume or the individual files are compressed or encrypted.
- ✗
The entry is hard-linked to another file.
Why it's wrong here
Hard links are managed by referencing the same MFT record. If a hard-linked file is deleted, the record is only freed if the link count reaches zero. The persistence of the FN attribute in a deleted record is independent of hard linking and is a function of NTFS's design regarding record cleanup.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.