GCFA NTFS Artifact Analysis Practice Question
An analyst is examining an NTFS volume and wants to identify the MFT entry for a specific file named 'report.docx'. The analyst knows the file's path but needs to locate its MFT record number to examine its attributes. Which NTFS metadata file should the analyst consult to map the file path to its MFT record number?
⚠ Common exam trap
The trap here is assuming that $MFT or $Bitmap can directly resolve a file path, when only directory index attributes contain the name-to-record mapping.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$Index allocation attributes within directory entries
To map a file path to its MFT record number, an examiner must traverse the directory index structures. Directories in NTFS use $INDEX_ROOT and $INDEX_ALLOCATION attributes to store entries that associate file names with MFT record numbers. Starting from the root directory and following each path component leads to the target file's record.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
$Index allocation attributes within directory entries
Why this is correct
NTFS directories store index entries in $INDEX_ROOT and $INDEX_ALLOCATION attributes. These entries map file names to their MFT record numbers. By traversing the directory hierarchy, an examiner can resolve the full path to the file's MFT record number. This is the correct method for path-to-record resolution.
- ✗
$Bitmap
Why it's wrong here
$Bitmap tracks cluster allocation and does not contain file names or directory structures. It cannot be used to resolve a file path to an MFT record number. Its purpose is to manage disk space allocation, not to provide a directory index.
- ✗
$MFT
Why it's wrong here
$MFT contains all MFT records but is not directly used to resolve a file path to a record number. While it stores the records themselves, it does not provide a directory index. To map a path, an examiner must traverse directory indexes, not scan the raw MFT.
- ✗
$Root
Why it's wrong here
$Root is the root directory index, but it only contains entries for files and directories directly under the root. For a file like 'report.docx' that may be in a subdirectory, the examiner would need to traverse multiple indexes, not just $Root. It is not a global path-to-record mapping.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.