GCFA Practice Question: Introduction to File System Timeline Forensics
An investigator is building a file system timeline for an NTFS volume from a Windows 10 workstation. The user claims a file was copied to an external drive at 14:00, but the file's NTFS Standard Information Attribute shows only a modification timestamp of 13:45. Which NTFS artifact should the investigator examine to determine when the filename was actually created or renamed on the volume?
⚠ Common exam trap
The trap here is assuming the $STANDARD_INFORMATION creation time always reflects the original file creation, when it can be altered and may not capture filename changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$FILE_NAME creation time
The $FILE_NAME attribute creation timestamp is updated when a filename is created or changed on an NTFS volume, making it a key artifact for detecting copy or rename activity. Unlike $STANDARD_INFORMATION, it is less commonly manipulated by user-mode APIs. In this case, it can reveal whether the filename appeared around 14:00, supporting or contradicting the user's statement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
$FILE_NAME creation time
Why this is correct
The $FILE_NAME attribute in the MFT records a timestamp that is updated when a filename is created or changed on the volume. For a copied or renamed file, this timestamp can reflect the time the filename entry was established, which may differ from the $STANDARD_INFORMATION creation time. In this scenario, it is the appropriate artifact to check for the filename creation event around 14:00.
- ✗
$LogFile transaction records
Why it's wrong here
$LogFile contains metadata transaction logs used for NTFS recovery, not a straightforward record of filename creation events. While it can contain file system operations, it is not the primary artifact for determining when a filename was created or renamed. Using it here would require complex parsing and may not directly answer the user's claim about the 14:00 copy.
- ✗
Volume Shadow Copy creation time
Why it's wrong here
Volume Shadow Copy creation time indicates when a shadow copy snapshot was made, not when a specific file or filename was created. It is useful for recovering previous versions but does not provide the filename creation timestamp needed in this scenario. It would not help verify the alleged 14:00 copy to external media.
- ✗
$STANDARD_INFORMATION creation time
Why it's wrong here
The $STANDARD_INFORMATION creation time can be manipulated by user-mode APIs and is not reliably updated on rename or copy operations. In this scenario, the modification timestamp is 13:45, but the filename creation event may be recorded elsewhere. Relying solely on this attribute would miss the rename or copy event and could incorrectly support or refute the user's 14:00 claim.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.