Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?

⚠ Common exam trap

Students frequently rely blindly on file access timestamps without checking file system mount options, leading to false assumptions about user activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mount options such as relatime or noatime suppress continuous updates to file access timestamps to improve performance.

The ext4 file system supports the noatime mount option, which disables the updating of access times whenever files are read. This optimization significantly reduces disk I/O overhead but blinds investigators to critical file access timelines, making it difficult to prove whether a specific binary was actually executed by a local user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ext4 journal aggressively overwrites inode metadata before user-space tools can parse the raw blocks.

    Why it's wrong here

    The ext4 journal records metadata transactions to ensure file system recovery after a crash, but it does not prematurely destroy inode structures before user-space analysis tools parse the disk. Forensic tools read the live structures and journal logs independently to reconstruct accurate historical event sequences.

  • ✗

    The operating system automatically randomizes inode timestamps every 24 hours to prevent precise profiling.

    Why it's wrong here

    Operating systems do not feature built-in timestamp randomization routines as a standard anti-forensic mechanism for ext4 file systems. Any unexpected alterations to inode metadata stem from specific administrative configurations, kernel features, or active malicious tampering by an attacker.

  • ✓

    Mount options such as relatime or noatime suppress continuous updates to file access timestamps to improve performance.

    Why this is correct

    Performance tuning options like relatime update access times only if the previous access time is older than the modification time or if it has been over a day. This intentional kernel behavior hides casual file reads, undermining traditional timeline analysis techniques used in incident response.

  • ✗

    The Sleuth Kit parser inherently misinterprets the 64-bit epoch time structures utilized by modern Linux kernels.

    Why it's wrong here

    The Sleuth Kit is continuously updated to fully support modern 64-bit epoch time representations found in contemporary Linux kernel implementations. Parsing errors are extremely rare and typically restricted to corrupted file system images rather than normal operational behavior.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.