Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

An investigator is analyzing a Windows 10 system and needs to correlate file system timestamps with other artifacts to build a comprehensive timeline. Which two of the following Windows artifacts can provide additional temporal context when combined with NTFS timestamps? (Choose two.)

⚠ Common exam trap

The trap here is selecting file system internal structures like $MFT or $LogFile, which are already part of the NTFS metadata, instead of external artifacts that provide additional context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prefetch files

Windows Event Logs and Prefetch files provide independent temporal data that can be correlated with NTFS timestamps. Event logs record system and user activities, while prefetch shows application execution. Together, they enrich a timeline by providing context for file system changes, helping analysts understand the sequence of events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Prefetch files

    Why this is correct

    Prefetch files (.pf) store information about applications executed on the system, including last run times and loaded files. They can be used to determine when an executable was run, which can be correlated with file creation or modification times. This helps establish cause and effect, such as an application creating or modifying files after execution. Prefetch is a key artifact for timeline enrichment.

  • ✗

    $MFT

    Why it's wrong here

    $MFT is the Master File Table itself, which contains the file system timestamps. It is the source of the timestamps being analyzed, not an additional artifact to correlate with. Using $MFT would be redundant and not provide independent temporal context. The question asks for other artifacts that can supplement NTFS timestamps, so $MFT is not appropriate.

  • ✗

    $LogFile

    Why it's wrong here

    $LogFile is an NTFS metadata journal that records file system changes. While it can provide detailed temporal information, it is part of the file system metadata, not an external artifact like event logs or prefetch. The question seeks additional Windows artifacts, and $LogFile is already an NTFS component. Thus, it does not fit the criterion of correlating with other artifacts.

  • ✓

    Windows Event Logs

    Why this is correct

    Windows Event Logs record system and application events with timestamps, such as logon events, service starts, and application errors. These can be correlated with file system timestamps to establish a sequence of user actions and system changes. For example, a logon event followed by file modifications can indicate user activity. This provides valuable context beyond file timestamps alone.

  • ✗

    Registry hive files

    Why it's wrong here

    Registry hive files contain configuration data and some timestamps, but they are not primarily used for temporal correlation with file system timestamps. While registry keys can have last write times, they are not as directly tied to file events as event logs or prefetch. In this context, registry hives are less useful for building a file-centric timeline compared to the other options.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.