GCFA File System Timeline Artifact Analysis Practice Question
An investigator is analyzing ext4 file system timelines extracted via fls and mactime. They notice that an inode's ctime was updated recently, but the atime and mtime remained unchanged. What does this specific combination of inode timestamp changes typically indicate in a Linux environment?
⚠ Common exam trap
Test-takers often assume that any file modification timestamp change includes the data blocks (mtime), forgetting that metadata-only operations alter the ctime independently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file permissions, ownership, or extended attributes were altered without modifying the underlying data blocks.
In ext4 file systems, the inode change time (ctime) updates whenever the inode metadata is modified, even if the file content (mtime) or access time (atime) remains untouched. Recognizing that metadata-only operations like permission changes or ownership transfers update ctime independently is critical for distinguishing between content tampering and permission hardening.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file contents were modified via a redirected write operation from a standard unprivileged user shell script.
Why it's wrong here
Modifying file contents through write operations inherently changes both the modification time (mtime) and the inode change time (ctime) simultaneously, making it impossible for only the ctime to update while the mtime remains completely unchanged.
- ✓
The file permissions, ownership, or extended attributes were altered without modifying the underlying data blocks.
Why this is correct
On ext4, ctime records inode metadata changes, so a recent ctime with unchanged atime and mtime indicates metadata such as permissions, ownership or extended attributes were modified without touching file content or access times, consistent with anti-forensic or administrative tampering.
- ✗
A background process read the file contents while the file system was mounted with strictatime options enabled.
Why it's wrong here
Reading file contents updates atime, not ctime alone; strictatime governs atime frequency, so this combination does not match. It is tempting because background reads are common, and would be correct if atime had changed while mtime and ctime stayed constant.
- ✗
The file was accessed and executed in memory using a shared library mapping that suppressed standard kernel logging.
Why it's wrong here
Shared library mapping still updates atime on access; no ext4 mechanism suppresses kernel timestamp logging for executed files. It is tempting because memory-resident execution suggests stealth, and would be correct where a rootkit or kernel module demonstrably intercepts timestamp updates.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.