GCFA NTFS Artifact Analysis Practice Question
An examiner images a Windows 10 workstation and notices that several user profile folders are out of order in the \$MFT when sorted by MFT record number, yet the $STANDARD_INFORMATION timestamps are consistent. The examiner suspects that entries were reordered or that records were freed and reused. Which NTFS artifact best supports determining whether MFT record numbers have been reassigned to different files over time?
⚠ Common exam trap
The trap here is assuming that timestamp attributes alone can prove MFT record reuse, when only the sequence number records allocation changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The $MFT record's sequence number, because it increments each time the record is allocated to a new file
The sequence number in an MFT file record is the key indicator of record reuse. It increases each time the record is allocated to a new file, so a higher sequence number than expected suggests the original file was deleted and the record was reassigned. Timestamps and $Bitmap do not preserve this allocation history.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The $MFT record's sequence number, because it increments each time the record is allocated to a new file
Why this is correct
Each MFT entry contains a sequence number that is incremented every time the record is allocated to a different file. By comparing the sequence number observed at acquisition with earlier journal or log entries, an examiner can determine whether the record number has been reused and how many times.
- ✗
The $STANDARD_INFORMATION attribute timestamps, because they are updated on every file access
Why it's wrong here
The $STANDARD_INFORMATION attribute holds MACB timestamps that the operating system updates during normal file operations. It does not record the history of MFT record reuse, so it cannot distinguish between a record that has always belonged to the same file and one that was reassigned after deletion.
- ✗
The volume's $Bitmap file, because it tracks the allocation status of every MFT record
Why it's wrong here
$Bitmap tracks which clusters on the volume are allocated or free, not the allocation history of individual MFT records. It can show whether a file's data clusters are currently in use, but it does not maintain a record-level history or sequence information for MFT entries.
- ✗
The $FILE_NAME attribute timestamps, because they persist across record reuse
Why it's wrong here
The $FILE_NAME attribute stores timestamps that are updated only on certain directory operations, and it does not maintain a history of prior record assignments. It can help detect timestamp discrepancies, but it cannot by itself prove that an MFT record number was previously allocated to a different file or directory.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.