GCFA Practice Question: Introduction to File System Timeline Forensics
An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?
⚠ Common exam trap
Students frequently rely blindly on file access timestamps without checking file system mount options, leading to false assumptions about user activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mount options such as relatime or noatime suppress continuous updates to file access timestamps to improve performance.
The ext4 file system supports the noatime mount option, which disables the updating of access times whenever files are read. This optimization significantly reduces disk I/O overhead but blinds investigators to critical file access timelines, making it difficult to prove whether a specific binary was actually executed by a local user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The ext4 journal aggressively overwrites inode metadata before user-space tools can parse the raw blocks.
Why it's wrong here
The ext4 journal records metadata transactions to ensure file system recovery after a crash, but it does not prematurely destroy inode structures before user-space analysis tools parse the disk. Forensic tools read the live structures and journal logs independently to reconstruct accurate historical event sequences.
- ✗
The operating system automatically randomizes inode timestamps every 24 hours to prevent precise profiling.
Why it's wrong here
Operating systems do not feature built-in timestamp randomization routines as a standard anti-forensic mechanism for ext4 file systems. Any unexpected alterations to inode metadata stem from specific administrative configurations, kernel features, or active malicious tampering by an attacker.
- ✓
Mount options such as relatime or noatime suppress continuous updates to file access timestamps to improve performance.
Why this is correct
Performance tuning options like relatime update access times only if the previous access time is older than the modification time or if it has been over a day. This intentional kernel behavior hides casual file reads, undermining traditional timeline analysis techniques used in incident response.
- ✗
The Sleuth Kit parser inherently misinterprets the 64-bit epoch time structures utilized by modern Linux kernels.
Why it's wrong here
The Sleuth Kit is continuously updated to fully support modern 64-bit epoch time representations found in contemporary Linux kernel implementations. Parsing errors are extremely rare and typically restricted to corrupted file system images rather than normal operational behavior.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.