Courseiva
NTFS Artifact Analysis →hardMultiple Select

GCFA NTFS Artifact Analysis Practice Question

An examiner is analyzing an NTFS volume from a Windows Server 2016 system that was abruptly powered off during a security incident. The examiner wants to determine recent file system changes that may not have been flushed to the $MFT. Which two NTFS artifacts should the examiner prioritize to reconstruct recent metadata operations? (Choose two.)

⚠ Common exam trap

The trap here is assuming that allocation maps like $Bitmap or security files like $Secure contain change history, when only $LogFile and $UsnJrnl record metadata operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$LogFile

$LogFile and $UsnJrnl both record metadata operations. $LogFile is a write-ahead log that captures transactions before they are committed to the $MFT, making it valuable after an unexpected shutdown. $UsnJrnl provides a persistent change journal that records file and directory modifications. Together they can reconstruct recent activity that may not be present in the $MFT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    $LogFile

    Why this is correct

    $LogFile records metadata transactions before they are committed to the $MFT. After a sudden power loss, it can contain recent file creation, deletion, and renaming operations that were not yet flushed. Parsing it allows reconstruction of file system changes that occurred just before the crash.

  • ✓

    $UsnJrnl

    Why this is correct

    $UsnJrnl (USN Journal) records changes to files and directories, including creation, deletion, and modification. It is stored in the $Extend directory and persists across reboots. It can provide a chronological record of recent file system activity that may not be reflected in the $MFT if the system crashed.

  • ✗

    $Secure

    Why it's wrong here

    $Secure (or $Secure:$SDS) stores security descriptors for files and directories. It does not log changes to file metadata such as creation or deletion. While it can be relevant for permissions analysis, it does not help reconstruct recent file system operations after a crash.

  • ✗

    $Bitmap

    Why it's wrong here

    $Bitmap tracks cluster allocation status but does not record metadata operations or file system changes. It can show which clusters are allocated but does not provide a timeline of file creations, deletions, or renames. Therefore, it is not useful for reconstructing recent metadata operations.

  • ✗

    $Boot

    Why it's wrong here

    $Boot contains the boot sector and bootstrap code for the volume. It does not store a history of file system changes or metadata operations. While it is essential for volume mounting, it provides no information about recent file activity or transactions.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.