GCFA Practice Question: Introduction to File System Timeline Forensics
An investigator is adding NTFS USN change journal records to a file system timeline on a Windows 10 workstation. The journal was captured live with fsutil usn readjournal and shows a record with Reason value 0x00000100 (DATA_OVERWRITE) for a user document. The investigator wants to determine whether the file content was actually altered at that moment. Which statement best describes what the USN record establishes?
⚠ Common exam trap
The trap here is assuming any USN record reflects a content change rather than reading the specific Reason flag.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The record proves the file's data stream was overwritten at the time of the USN entry and can anchor the timeline for content modification.
USN journal records capture specific change reasons at the moment they occur, and DATA_OVERWRITE specifically denotes that file data was overwritten. When the journal is intact and not wrapped, this gives the investigator a strong anchor for content modification. Other flags correspond to metadata or lifecycle events, so the reason code must be read literally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The record only shows that the file was opened for read access, because DATA_OVERWRITE is logged when the data stream is read.
Why it's wrong here
DATA_OVERWRITE is not generated by read access; read access does not produce a USN journal entry at all. It is emitted when existing data in the file is overwritten, so treating it as a read event would incorrectly place a content modification on the timeline and mislead the investigation.
- ✗
The record indicates only that the file's MFT metadata was updated, not that the file data stream changed.
Why it's wrong here
Metadata updates such as timestamp or attribute changes are logged with different Reason flags, for example BASIC_INFO_CHANGE or the various attribute flags. DATA_OVERWRITE specifically reflects a change to the data stream, so dismissing it as metadata-only ignores the actual meaning of the flag.
- ✗
The record confirms the file was deleted and then re-created with the same name at the recorded time.
Why it's wrong here
Deletion and creation produce distinct USN Reason values such as FILE_DELETE and FILE_CREATE, not DATA_OVERWRITE. The flag observed here relates to overwriting existing content, so interpreting it as a delete and recreate would misrepresent the file's lifecycle on the timeline.
- ✓
The record proves the file's data stream was overwritten at the time of the USN entry and can anchor the timeline for content modification.
Why this is correct
DATA_OVERWRITE (0x00000100) indicates that data in the file was overwritten at the recorded time. Because the USN journal is written when the change occurs, this record is a reliable anchor for content modification on the timeline, assuming the journal has not wrapped and overwritten older records.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.