GCFA Practice Question: Introduction to File System Timeline Forensics
An investigator is analyzing a Windows 10 system and needs to correlate file system timestamps with other artifacts to build a comprehensive timeline. Which two of the following Windows artifacts can provide additional temporal context when combined with NTFS timestamps? (Choose two.)
⚠ Common exam trap
The trap here is selecting file system internal structures like $MFT or $LogFile, which are already part of the NTFS metadata, instead of external artifacts that provide additional context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prefetch files
Windows Event Logs and Prefetch files provide independent temporal data that can be correlated with NTFS timestamps. Event logs record system and user activities, while prefetch shows application execution. Together, they enrich a timeline by providing context for file system changes, helping analysts understand the sequence of events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Prefetch files
Why this is correct
Prefetch files (.pf) store information about applications executed on the system, including last run times and loaded files. They can be used to determine when an executable was run, which can be correlated with file creation or modification times. This helps establish cause and effect, such as an application creating or modifying files after execution. Prefetch is a key artifact for timeline enrichment.
- ✗
$MFT
Why it's wrong here
$MFT is the Master File Table itself, which contains the file system timestamps. It is the source of the timestamps being analyzed, not an additional artifact to correlate with. Using $MFT would be redundant and not provide independent temporal context. The question asks for other artifacts that can supplement NTFS timestamps, so $MFT is not appropriate.
- ✗
$LogFile
Why it's wrong here
$LogFile is an NTFS metadata journal that records file system changes. While it can provide detailed temporal information, it is part of the file system metadata, not an external artifact like event logs or prefetch. The question seeks additional Windows artifacts, and $LogFile is already an NTFS component. Thus, it does not fit the criterion of correlating with other artifacts.
- ✓
Windows Event Logs
Why this is correct
Windows Event Logs record system and application events with timestamps, such as logon events, service starts, and application errors. These can be correlated with file system timestamps to establish a sequence of user actions and system changes. For example, a logon event followed by file modifications can indicate user activity. This provides valuable context beyond file timestamps alone.
- ✗
Registry hive files
Why it's wrong here
Registry hive files contain configuration data and some timestamps, but they are not primarily used for temporal correlation with file system timestamps. While registry keys can have last write times, they are not as directly tied to file events as event logs or prefetch. In this context, registry hives are less useful for building a file-centric timeline compared to the other options.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.