Courseiva

GCFA File System Timeline Artifact Analysis Practice Question

An investigator analyzing an NTFS volume notices that a file's $STANDARD_INFORMATION MACB timestamps significantly differ from its $FILE_NAME timestamps. The $FILE_NAME modification time predates the $STANDARD_INFORMATION modification time. What is the most reliable forensic interpretation of this discrepancy?

⚠ Common exam trap

Candidates often incorrectly assume that the $STANDARD_INFORMATION attribute is the 'truth' when discrepancies exist, ignoring the kernel-level reliability of the $FILE_NAME attribute in detecting timestomping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file was likely subjected to time-stomping where user-space tools altered the $STANDARD_INFORMATION attributes, leaving the original $FILE_NAME timestamps intact.

Timestamp discrepancies between the $STANDARD_INFORMATION and $FILE_NAME attributes often indicate file manipulation, copying, or time-stomping. Since the $STANDARD_INFORMATION attribute can be easily modified by user-space APIs while the $FILE_NAME attribute is managed directly by the NTFS driver, comparing both provides crucial insight into anti-forensic activities and accurate timeline reconstruction during incident response investigations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file was compressed using NTFS compression, which automatically updates the $STANDARD_INFORMATION modification timestamp while leaving $FILE_NAME untouched.

    Why it's wrong here

    NTFS compression alters physical allocation structures rather than selectively targeting $STANDARD_INFORMATION timestamps. Compression events update both attribute sets during metadata modification, meaning this behavior cannot account for intentional divergence between the two critical time recording locations.

  • ✗

    An automated defragmentation utility ran on the volume, updating the high-level metadata without altering the underlying filename structure.

    Why it's wrong here

    Defragmentation relocates clusters and updates $STANDARD_INFORMATION allocation metadata, but it never rewrites $FILE_NAME timestamps, so it cannot create a discrepancy where $FILE_NAME modification predates $STANDARD_INFORMATION. It is tempting because defrag does touch NTFS metadata, but the correct interpretation is deliberate timestamp manipulation via $STANDARD_INFORMATION editing.

  • ✓

    The file was likely subjected to time-stomping where user-space tools altered the $STANDARD_INFORMATION attributes, leaving the original $FILE_NAME timestamps intact.

    Why this is correct

    User-space anti-forensic tools typically modify only the easily accessible $STANDARD_INFORMATION attribute. Because the NTFS kernel driver maintains the $FILE_NAME attribute during standard renaming and creation actions, the older $FILE_NAME timestamp frequently survives, exposing the tampering attempt to investigators.

  • ✗

    The operating system experienced an unclean shutdown, causing the lazy writer thread to flush $STANDARD_INFORMATION changes out of synchronization with $FILE_NAME.

    Why it's wrong here

    Lazy writer flushes affect file data and metadata timing, but an unclean shutdown cannot make $FILE_NAME modification time predate $STANDARD_INFORMATION modification time, since $FILE_NAME is only written at creation or rename. This option tempts because NTFS journal replay after crashes does resynchronise metadata, yet that produces matching, not reversed, timestamps.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.