GCFA NTFS Artifact Analysis Practice Question
An analyst is examining a Windows 10 system where a user deleted several files containing sensitive data. The analyst needs to recover the file content and determines that the $DATA attribute of the MFT record for one deleted file is resident. What does this indicate about the file's data and its recoverability?
⚠ Common exam trap
It's easy for candidates to confuse resident data with external cluster storage, leading an analyst to attempt carving instead of examining the MFT record itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file content is stored within the MFT record itself and may be recoverable if the record has not been overwritten
A resident $DATA attribute means the file's content is stored directly within the MFT record because it is small enough. After deletion, the record is marked free but the data persists until the record is reused. An examiner can parse the MFT entry to recover the content, provided the record has not been overwritten.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file content is stored in clusters outside the MFT and can be recovered by carving the volume
Why it's wrong here
A resident $DATA attribute indicates the content is stored inside the MFT record, not in external clusters. Carving the volume for file signatures would not be the primary method for resident data; instead, the MFT record itself must be examined. Carving is more relevant for non-resident files.
- ✓
The file content is stored within the MFT record itself and may be recoverable if the record has not been overwritten
Why this is correct
A resident $DATA attribute means the file's content is small enough to fit inside the MFT record. When the file is deleted, the record is marked as free but the data remains until the record is reallocated. Therefore, the content may still be recoverable by parsing the MFT entry.
- ✗
The file content is compressed and requires the $COMPRESSION attribute to be decoded
Why it's wrong here
The presence of a resident $DATA attribute does not imply compression. Compression is indicated by specific flags in the $DATA attribute header and often results in non-resident storage. Resident data is simply stored inline and is not inherently compressed, so no decompression is needed.
- ✗
The file content is encrypted and requires the $LOGGED_UTILITY_STREAM attribute to be decrypted
Why it's wrong here
Encryption is indicated by the presence of the $LOGGED_UTILITY_STREAM attribute used by EFS, not by the resident status of $DATA. A resident $DATA attribute simply means the content fits in the MFT record; it does not imply encryption or the need for decryption.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.