GCFA NTFS Artifact Analysis Practice Question
An analyst is examining an NTFS volume from a Windows Server 2019 system that was used as a file server. A file critical to the investigation is missing from the directory listing, but the analyst suspects the file was recently deleted and its MFT entry has not been overwritten. Which NTFS artifact should the analyst examine to recover the file's full path and name if the MFT entry is still intact?
⚠ Common exam trap
The trap here is assuming that the USN Journal or $Bitmap contains the full path, when in fact the $FILE_NAME attribute in the MFT record is the authoritative source for the file's name and parent reference.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$FILE_NAME attribute within the file's MFT record
The $FILE_NAME attribute in the MFT record contains the file's name and a reference to its parent directory's MFT entry. By parsing this attribute and then locating the parent MFT entry, an analyst can reconstruct the full path. Other artifacts like $Bitmap or $UsnJrnl may provide supporting information but do not directly contain the full path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
$UsnJrnl:$J stream
Why it's wrong here
The USN Journal ($UsnJrnl:$J) records changes to files and directories, including deletion events, and may contain the file name and parent MFT reference. However, it does not store the full path directly; it requires mapping the parent reference to the MFT to reconstruct the path. Moreover, the journal may have wrapped and lost older records. It is not the most direct artifact for recovering the full path when the MFT entry is intact.
- ✓
$FILE_NAME attribute within the file's MFT record
Why this is correct
The $FILE_NAME attribute in an MFT record stores the file's name and a reference to the parent directory's MFT entry. Even after deletion, if the MFT record is not overwritten, this attribute remains and can be used to reconstruct the full path by following the parent reference. This is the primary artifact for recovering the name and location of a deleted file when the MFT entry is intact.
- ✗
$INDEX_ROOT attribute of the parent directory
Why it's wrong here
The $INDEX_ROOT attribute of a directory contains the root node of the B-tree index for that directory. If a file is deleted, its entry is removed from the index, so the $INDEX_ROOT would no longer contain the file name. While it can show other files in the directory, it cannot recover the deleted file's name or path. Thus it is not the correct artifact for this scenario.
- ✗
$Bitmap metadata file
Why it's wrong here
The $Bitmap file tracks which clusters on the volume are allocated or free. It does not store file names or directory paths. While it can indicate whether the file's clusters have been reallocated, it cannot provide the file's name or parent directory. Therefore, it is not useful for recovering the path of a deleted file.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.