Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

An investigator is analyzing an NTFS volume from a Windows Server 2016 system that was recently compromised. The attacker used a tool to modify file timestamps to evade detection. The investigator notices that the $STANDARD_INFORMATION timestamps for a suspicious executable are all set to 2018-01-01, while the $FILE_NAME timestamps remain at 2021-06-15. The $MFT entry number is 12345. What is the most accurate conclusion regarding the timestamp manipulation?

⚠ Common exam trap

The trap here is assuming that any timestamp manipulation affects both $STANDARD_INFORMATION and $FILE_NAME equally, when in fact many tools only modify the $STANDARD_INFORMATION attribute.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The attacker used a tool that only modifies $STANDARD_INFORMATION timestamps, and the $FILE_NAME timestamps are likely original and reliable.

The correct answer is the option stating that the attacker modified only $STANDARD_INFORMATION timestamps. Common timestomping tools like timestomp or SetMace often alter the $STANDARD_INFORMATION attribute without updating the $FILE_NAME attribute. This creates a discrepancy where $STANDARD_INFORMATION shows an earlier, uniform date while $FILE_NAME retains the original timestamp. Investigators should compare both sets of timestamps and treat the $FILE_NAME values as more reliable when manipulation is suspected, as they are harder to modify without specialized tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Both sets of timestamps were modified, and the investigator cannot determine which one is original without additional artifacts.

    Why it's wrong here

    This is incorrect because the pattern of all $STANDARD_INFORMATION timestamps set to a single date is a strong indicator of manipulation, while the $FILE_NAME timestamps appear consistent and plausible. While it is theoretically possible that both were modified, the scenario does not provide evidence of that. The investigator can reasonably conclude that the $STANDARD_INFORMATION values are suspect and the $FILE_NAME values are more likely original, especially given the known behavior of common timestomping tools.

  • ✗

    The $FILE_NAME timestamps were modified by the attacker, and the $STANDARD_INFORMATION timestamps are the original ones.

    Why it's wrong here

    This is incorrect because the scenario states that the $STANDARD_INFORMATION timestamps are all set to a single date (2018-01-01), which is a common artifact of timestamp manipulation tools that set all four timestamps to the same value. In contrast, the $FILE_NAME timestamps show a more recent and plausible date (2021-06-15). If the attacker had modified the $FILE_NAME timestamps, they would likely also show the manipulated date or a similarly suspicious uniform value. The evidence points to $STANDARD_INFORMATION being the altered attribute.

  • ✗

    The timestamps are consistent with normal system behavior, and no manipulation occurred.

    Why it's wrong here

    This is incorrect because normal system behavior does not result in all four $STANDARD_INFORMATION timestamps being set to a single date while $FILE_NAME timestamps remain at a different, more recent date. Such a uniform and earlier date is a classic sign of timestomping. Additionally, the scenario explicitly mentions that the attacker used a tool to modify timestamps, so the investigator should interpret the discrepancy as evidence of manipulation, not normal activity.

  • ✓

    The attacker used a tool that only modifies $STANDARD_INFORMATION timestamps, and the $FILE_NAME timestamps are likely original and reliable.

    Why this is correct

    This is correct because many timestamp manipulation tools, such as timestomp, target only the $STANDARD_INFORMATION attribute by default. The $FILE_NAME attribute timestamps are stored in the directory entry and are not always updated by such tools unless they specifically target them. Therefore, the discrepancy between the two sets of timestamps strongly suggests that the $STANDARD_INFORMATION values were altered, while the $FILE_NAME values may still reflect the original file creation or modification times. The investigator should prioritize the $FILE_NAME timestamps as more reliable in this scenario.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.