Courseiva
NTFS Artifact Analysis →hardMultiple Choice

GCFA NTFS Artifact Analysis Practice Question

An investigator is analyzing an NTFS volume and finds that a file's $DATA attribute is non-resident and its data runs point to clusters that are currently allocated to a different file. The file's size is 10 KB. What is the most likely explanation for this situation?

⚠ Common exam trap

The trap here is attributing the cluster overlap to a standard NTFS feature like compression or sparse files, when it actually indicates metadata corruption or tampering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file's data runs are corrupt or the MFT entry is inconsistent, possibly due to disk corruption or deliberate manipulation.

A non-resident $DATA attribute with data runs pointing to clusters allocated to another file is an abnormal condition. Standard NTFS features like compression, sparse files, or encryption do not cause such overlap. This inconsistency suggests corruption or intentional manipulation, requiring further forensic examination to determine the cause and potential data recovery challenges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file is encrypted, and the data runs are stored in the $EFS attribute instead of $DATA.

    Why it's wrong here

    Encrypted files using EFS have an $EFS attribute that contains encryption metadata, but the file data remains in the $DATA attribute, albeit encrypted. Data runs still point to allocated clusters. Overlap with another file's clusters is not a characteristic of EFS encryption.

  • ✓

    The file's data runs are corrupt or the MFT entry is inconsistent, possibly due to disk corruption or deliberate manipulation.

    Why this is correct

    If a file's non-resident $DATA attribute points to clusters that are currently allocated to another file, this indicates an inconsistency in the file system metadata. This can occur from disk corruption, software bugs, or deliberate tampering. It is not a normal state for any standard NTFS feature.

  • ✗

    The file is sparse, and the data runs include sparse ranges that map to clusters not physically allocated.

    Why it's wrong here

    Sparse files have data runs with sparse ranges, but those ranges indicate unallocated clusters, not clusters allocated to another file. The scenario states the clusters are allocated to a different file, so sparse file behavior does not apply.

  • ✗

    The file is compressed, and the data runs are stored in a separate $DATA attribute named $TXF_DATA.

    Why it's wrong here

    NTFS compression uses a single $DATA attribute with the compressed flag set, not a separate $TXF_DATA attribute. $TXF_DATA is related to transactional NTFS (TxF) and is not used for compression. The scenario describes overlapping clusters, which is unrelated to compression.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.