GCFA Practice Question: Introduction to File System Timeline Forensics
An investigator is preparing to analyze a Windows 10 workstation's NTFS volume using a forensic tool that reads the master file table (MFT) directly. The goal is to build a timeline that includes timestamps for files that were deleted before the acquisition. Which artifact should the investigator primarily rely on to recover timestamps for deleted files?
⚠ Common exam trap
The trap here is assuming that deleted files leave no timestamp evidence once their MFT entry is marked as unallocated, when in fact the record content often persists until reuse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The $MFT file and its unallocated MFT entry records
Unallocated MFT entries preserve the $STANDARD_INFORMATION and $FILE_NAME attributes of deleted files until those entries are reused. By parsing the $MFT, including slack and unallocated records, an analyst can recover the four MACB timestamps for files that no longer exist in the active file system, which is essential for a complete forensic timeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The $LogFile transaction log
Why it's wrong here
The $LogFile contains metadata transaction records used for NTFS recovery. While it may reference MFT record changes, it is not designed to provide a comprehensive set of timestamps for deleted files and is difficult to parse for timeline purposes. It is not the primary source for deleted file timestamps.
- ✓
The $MFT file and its unallocated MFT entry records
Why this is correct
Deleted file metadata often remains in unallocated MFT entries until overwritten. Parsing the $MFT, including unallocated entries, allows recovery of $STANDARD_INFORMATION and $FILE_NAME timestamps for deleted files, enabling their inclusion in the timeline even though the file content is gone.
- ✗
The $UsnJrnl:$J change journal
Why it's wrong here
The USN change journal records changes such as creation, deletion, and rename events for files on the volume, but it does not retain the full set of MACB timestamps from the MFT. It can indicate that a deletion occurred, yet it cannot reconstruct the original creation, modification, and access times for the deleted file.
- ✗
The $Bitmap allocation file
Why it's wrong here
The $Bitmap tracks which clusters on the volume are allocated or free. It can help identify unallocated space but does not contain file names or timestamps. It cannot provide the temporal data needed to place a deleted file in the timeline.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.