GCFA File System Timeline Artifact Analysis Practice Question
An analyst is examining an NTFS volume and notices a discrepancy where the $Standard_Information attribute modification time is earlier than the $File_Name attribute modification time. What does this specific pattern indicate about the file's history?
⚠ Common exam trap
Many candidates confuse which NTFS attribute is easily modified by user-level APIs versus the kernel, leading them to misidentify the original timeline during timestomping analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file's metadata was likely modified by an anti-forensics tool.
This pattern is a classic indicator of 'timestomping' or anti-forensics activity. The $Standard_Information attribute is easily modified by user-level APIs, while the $File_Name attribute is typically updated only by the system kernel during move or rename operations. When an attacker resets the $Standard_Information timestamps to blend in, the $File_Name attribute often retains the true metadata, revealing the manipulation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file was compressed by the NTFS engine.
Why it's wrong here
NTFS compression does not selectively update file attributes in a way that creates this specific temporal discrepancy. While compression alters the physical storage of data clusters, the metadata attributes $Standard_Information and $File_Name are maintained independently of the compression status or the algorithm applied to the resident data.
- ✗
The file was moved across different NTFS volumes.
Why it's wrong here
When a file is moved between volumes, the $File_Name attribute is newly created on the destination volume. This process resets the $File_Name timestamps to the time of the move, which does not result in the $Standard_Information attribute predating the $File_Name attribute in the manner described.
- ✓
The file's metadata was likely modified by an anti-forensics tool.
Why this is correct
User-mode tools modify the $Standard_Information attribute to hide execution or creation time. Because these tools cannot easily modify the $File_Name attribute—which is protected by the Windows kernel—the discrepancy emerges. This signature is a primary artifact used by responders to identify malicious file manipulation and temporal masking.
- ✗
The file was recently recovered from the Recycle Bin.
Why it's wrong here
Restoring a file from the Recycle Bin generally restores the original metadata stored within the $I30 index and the file record. It does not intentionally trigger a divergence between $Standard_Information and $File_Name attributes. If a discrepancy exists, it is likely unrelated to the standard restoration process.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.