Courseiva
NTFS Artifact Analysis →hardMultiple Choice

GCFA NTFS Artifact Analysis Practice Question

An analyst is examining an NTFS volume from a Windows Server 2019 system that was used as a file server. A file critical to the investigation is missing from the directory listing, but the analyst suspects the file was recently deleted and its MFT entry has not been overwritten. Which NTFS artifact should the analyst examine to recover the file's full path and name if the MFT entry is still intact?

⚠ Common exam trap

The trap here is assuming that the USN Journal or $Bitmap contains the full path, when in fact the $FILE_NAME attribute in the MFT record is the authoritative source for the file's name and parent reference.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$FILE_NAME attribute within the file's MFT record

The $FILE_NAME attribute in the MFT record contains the file's name and a reference to its parent directory's MFT entry. By parsing this attribute and then locating the parent MFT entry, an analyst can reconstruct the full path. Other artifacts like $Bitmap or $UsnJrnl may provide supporting information but do not directly contain the full path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    $UsnJrnl:$J stream

    Why it's wrong here

    The USN Journal ($UsnJrnl:$J) records changes to files and directories, including deletion events, and may contain the file name and parent MFT reference. However, it does not store the full path directly; it requires mapping the parent reference to the MFT to reconstruct the path. Moreover, the journal may have wrapped and lost older records. It is not the most direct artifact for recovering the full path when the MFT entry is intact.

  • ✓

    $FILE_NAME attribute within the file's MFT record

    Why this is correct

    The $FILE_NAME attribute in an MFT record stores the file's name and a reference to the parent directory's MFT entry. Even after deletion, if the MFT record is not overwritten, this attribute remains and can be used to reconstruct the full path by following the parent reference. This is the primary artifact for recovering the name and location of a deleted file when the MFT entry is intact.

  • ✗

    $INDEX_ROOT attribute of the parent directory

    Why it's wrong here

    The $INDEX_ROOT attribute of a directory contains the root node of the B-tree index for that directory. If a file is deleted, its entry is removed from the index, so the $INDEX_ROOT would no longer contain the file name. While it can show other files in the directory, it cannot recover the deleted file's name or path. Thus it is not the correct artifact for this scenario.

  • ✗

    $Bitmap metadata file

    Why it's wrong here

    The $Bitmap file tracks which clusters on the volume are allocated or free. It does not store file names or directory paths. While it can indicate whether the file's clusters have been reallocated, it cannot provide the file's name or parent directory. Therefore, it is not useful for recovering the path of a deleted file.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.