Courseiva
NTFS Artifact Analysis →mediumMultiple Choice

GCFA NTFS Artifact Analysis Practice Question

An analyst is examining the USN Journal. What is the primary purpose of this file in the context of NTFS forensic analysis?

⚠ Common exam trap

Many analysts mistakenly believe the USN Journal is a security log for user actions, failing to identify that it is a filesystem-level log of all changes to metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Providing a history of file system changes.

The USN Journal ($UsnJrnl) provides a chronological log of all changes made to files and directories on an NTFS volume. For forensics, it is invaluable because it captures activity that may no longer be reflected in the current MFT, such as the creation and subsequent deletion of files, or directory renames, providing a persistent history of disk modifications for timeline reconstruction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Storing encrypted file passwords.

    Why it's wrong here

    The USN Journal does not store passwords or encryption keys. It only logs metadata changes regarding file operations like creation, modification, and deletion. Attempting to locate encryption credentials within the USN Journal will be unsuccessful as it lacks the security context required for storing sensitive user authentication information.

  • ✓

    Providing a history of file system changes.

    Why this is correct

    The USN Journal logs every change made to files and directories on the volume. By parsing this file, investigators can reconstruct a timeline of events even if the original files were deleted. It is a critical artifact for understanding the sequence of events during a security incident.

  • ✗

    Maintaining the B-tree structure of directories.

    Why it's wrong here

    Directory B-trees are managed by the $INDEX_ROOT and $INDEX_ALLOCATION attributes within the MFT. The USN Journal tracks changes to the filesystem state but does not participate in the structural maintenance of the directory hierarchy itself. It is a passive logging mechanism, not an active structure manager.

  • ✗

    Tracking user login and logout sessions.

    Why it's wrong here

    The USN Journal monitors filesystem activity, not user authentication sessions. Tracking user logins is handled by the Windows Security Event logs. While a user action might trigger a file change that the USN journal records, the journal itself contains no information about the user's active session state.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.