Courseiva

GCFA File System Timeline Artifact Analysis Practice Question

An investigator is examining a Windows 10 workstation's NTFS volume with Sleuth Kit tools. They run fls against the volume and observe that a deleted file's MFT entry still shows a valid $FILE_NAME attribute referencing the parent directory, but the $DATA attribute's resident content is now zero-filled. Which interpretation of this artifact is MOST accurate for the timeline?

⚠ Common exam trap

The trap here is assuming a zeroed $DATA attribute always means the MFT record was reallocated, when an inactive record with preserved $FILE_NAME commonly indicates deletion without reuse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file was deleted, and the resident data stream was zeroed during deletion or by subsequent system activity while the MFT entry itself was not yet reused.

A deleted NTFS file often leaves its MFT record intact until reallocation, with $FILE_NAME still referencing the parent directory. Zeroed resident $DATA indicates the content was cleared during or after deletion, not that the record was reused. Analysts should treat the entry as evidence of a deletion event and avoid claiming recoverability of the data stream from this record alone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The file was deleted, and the resident data stream was zeroed during deletion or by subsequent system activity while the MFT entry itself was not yet reused.

    Why this is correct

    When a file is deleted on NTFS, the MFT record is marked inactive but the entry can persist until reused. Resident $DATA content may be zeroed by the deletion process or later activity, while $FILE_NAME metadata survives in the record. This supports establishing a deletion event in the timeline even though the file content is unrecoverable from the resident stream.

  • ✗

    The file is a sparse file whose allocated ranges were trimmed by the NTFS compression engine, leaving a valid $FILE_NAME with empty content.

    Why it's wrong here

    Sparse files report valid data runs for allocated ranges, and compression uses $DATA with compression units, not zero-filled resident content. A sparse or compressed file would not appear as a deleted entry with a preserved $FILE_NAME and zeroed resident data. This explanation mischaracterizes NTFS compression and sparse allocation behavior, leading to an incorrect timeline conclusion.

  • ✗

    The file was moved to a different directory, causing NTFS to clear the $DATA attribute and retain the $FILE_NAME attribute as a tombstone.

    Why it's wrong here

    A move within the same NTFS volume does not clear the $DATA attribute; NTFS updates the $FILE_NAME parent reference and the record remains active. Moves do not produce zeroed resident data with a preserved $FILE_NAME. This artifact pattern reflects deletion, not relocation, so treating it as a move would misplace the event in the timeline.

  • ✗

    The MFT record was reallocated to a new file, which overwrote only the $DATA attribute while preserving the $FILE_NAME attribute.

    Why it's wrong here

    MFT record reallocation would normally reset the record header, sequence number, and all attributes, not selectively preserve $FILE_NAME while zeroing only $DATA. This pattern of a still-valid filename with zeroed resident data is more consistent with file deletion plus content clearing, not full record reuse. Investigators should verify the record header flags and sequence number before concluding reallocation occurred.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.