Courseiva
NTFS Artifact Analysis →easyMultiple Choice

GCFA NTFS Artifact Analysis Practice Question

An analyst is examining an NTFS volume and wants to identify the MFT entry for a specific file named 'report.docx'. The analyst knows the file's path but needs to locate its MFT record number to examine its attributes. Which NTFS metadata file should the analyst consult to map the file path to its MFT record number?

⚠ Common exam trap

The trap here is assuming that $MFT or $Bitmap can directly resolve a file path, when only directory index attributes contain the name-to-record mapping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$Index allocation attributes within directory entries

To map a file path to its MFT record number, an examiner must traverse the directory index structures. Directories in NTFS use $INDEX_ROOT and $INDEX_ALLOCATION attributes to store entries that associate file names with MFT record numbers. Starting from the root directory and following each path component leads to the target file's record.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    $Index allocation attributes within directory entries

    Why this is correct

    NTFS directories store index entries in $INDEX_ROOT and $INDEX_ALLOCATION attributes. These entries map file names to their MFT record numbers. By traversing the directory hierarchy, an examiner can resolve the full path to the file's MFT record number. This is the correct method for path-to-record resolution.

  • ✗

    $Bitmap

    Why it's wrong here

    $Bitmap tracks cluster allocation and does not contain file names or directory structures. It cannot be used to resolve a file path to an MFT record number. Its purpose is to manage disk space allocation, not to provide a directory index.

  • ✗

    $MFT

    Why it's wrong here

    $MFT contains all MFT records but is not directly used to resolve a file path to a record number. While it stores the records themselves, it does not provide a directory index. To map a path, an examiner must traverse directory indexes, not scan the raw MFT.

  • ✗

    $Root

    Why it's wrong here

    $Root is the root directory index, but it only contains entries for files and directories directly under the root. For a file like 'report.docx' that may be in a subdirectory, the examiner would need to traverse multiple indexes, not just $Root. It is not a global path-to-record mapping.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.