GCFA · domain
File System Timeline Artifact Analysis
This GCFA domain covers reconstructing activity from file system metadata across NTFS and ext4. Candidates use fls, mactime, and $MFT parsing to interpret MACB timestamps, $STANDARD_INFORMATION versus $FILE_NAME discrepancies, and anti-forensic timestamp manipulation. Questions present artifact combinations and require correct interpretation of what each timestamp change implies about user or system activity.
Focused practice
Practice File System Timeline Artifact Analysis questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about File System Timeline Artifact Analysis
A candidate must interpret MACB timestamp combinations across NTFS and ext4 artifacts and explain what each change indicates. The most important thing is distinguishing legitimate system updates from anti-forensic manipulation by cross-checking $STANDARD_INFORMATION against $FILE_NAME timestamps and inode metadata.
Interpreting ext4 inode ctime, atime, and mtime changes via fls and mactime output
Comparing NTFS $STANDARD_INFORMATION MACB timestamps against $FILE_NAME timestamps for discrepancies
Using $MFT record 0 and $MFT metadata to anchor NTFS timeline construction
Recognizing anti-forensic techniques such as timestomping and secure deletion that alter file system timelines
Watch out for
Common File System Timeline Artifact Analysis exam traps
- ▸Assuming a changed ctime always means content modification, when metadata-only changes like permissions or ownership also update ctime.
- ▸Treating $STANDARD_INFORMATION timestamps as authoritative without checking $FILE_NAME, which timestomping tools often leave inconsistent.
- ▸Overlooking $MFT record 0 or $MFTMirr when building timelines, missing metadata that establishes the volume's baseline.
Question index
All File System Timeline Artifact Analysis questions (20)
Click any question to see the full explanation, or start a practice session above.
An analyst is examining an NTFS volume and notices a discrepancy where the $Standard_Information attribute modification time is earlier than the $File_Name attribute modification time. What does this specific pattern indicate about the file's history?
Medium2An analyst is using The Sleuth Kit to analyze an NTFS image. They run `fls -r -m C:/` to generate a body file and then `mactime -b bodyfile -d` to produce a timeline. They notice that the timeline includes entries for files with a '$' prefix, such as $MFT, $LogFile, and $Bitmap. What is the most appropriate action for the analyst to take regarding these entries?
Easy3A forensic analyst is examining an ext4 file system image from a Linux server. Using fls and istat from The Sleuth Kit, the analyst sees a deleted file whose inode still contains block pointers that now point to blocks reallocated to another file. The analyst wants to determine whether the deleted file's content can be recovered intact. Which ext4 condition best explains why the content is likely unrecoverable?
Medium4What is the primary function of the $LogFile in an NTFS file system?
Easy5An analyst is examining a file that was deleted. Why is the 'File Name' (FN) attribute in the MFT still potentially readable?
Medium6An investigator is examining a Windows 10 workstation's NTFS volume with Sleuth Kit tools. They run fls against the volume and observe that a deleted file's MFT entry still shows a valid $FILE_NAME attribute referencing the parent directory, but the $DATA attribute's resident content is now zero-filled. Which interpretation of this artifact is MOST accurate for the timeline?
Medium7An analyst is reviewing an NTFS file system timeline and notices that a file's $STANDARD_INFORMATION modified timestamp is 2024-01-15 10:00:00, while its $FILE_NAME modified timestamp is 2024-01-15 09:55:00. The file's $MFT record shows a USN journal entry indicating a rename operation at 09:54:00. There is no other metadata. Which of the following is the most likely explanation for the 5-minute difference between the two modified timestamps?
Hard8An examiner is reviewing an APFS volume from a macOS 13 system. Using a timeline tool that parses APFS metadata, the analyst observes a file whose inode has an added date (birth time) earlier than its modified time, and the file's data stream shows a sparse extent. The case requires establishing the earliest credible creation time for the file. Which APFS attribute should the analyst rely on as the file's creation time?
Hard9When analyzing the $LogFile in NTFS, what is the significance of the undo and redo operations recorded in the transaction logs for timeline reconstruction?
Hard10An investigator is analyzing ext4 file system timelines extracted via fls and mactime. They notice that an inode's ctime was updated recently, but the atime and mtime remained unchanged. What does this specific combination of inode timestamp changes typically indicate in a Linux environment?
Medium11A forensic analyst is examining a Windows 10 system and finds a prefetch file named `CMD.EXE-1234ABCD.pf`. The analyst wants to determine the last time the program was executed. Which timestamp in the prefetch file should the analyst use?
Easy12Which of the following is true regarding the 'MFT Change' timestamp?
Medium13Which TWO of the following actions are considered 'anti-forensic' techniques that directly impact file system timeline analysis?
Hard14An investigator is analyzing MACB timelines on a Windows system and needs to differentiate between a file being copied versus being moved within the same NTFS volume. Which timeline artifact behavior distinguishes an intra-volume file move from a file copy operation?
Hard15An investigator analyzing an NTFS volume notices that a file's $STANDARD_INFORMATION MACB timestamps significantly differ from its $FILE_NAME timestamps. The $FILE_NAME modification time predates the $STANDARD_INFORMATION modification time. What is the most reliable forensic interpretation of this discrepancy?
Medium16Refer to the exhibit. What can be inferred about the file activity?
Hard17A forensic analyst is creating a timeline from an NTFS volume and wants to include the $MFT's record number 0, which contains metadata about the MFT itself. What is the primary purpose of including this record in the timeline?
Easy18During an investigation of a Windows system, an analyst is reviewing a supertimeline and observes that a suspicious executable's $STANDARD_INFORMATION timestamps are all set to a date years before the operating system was installed, while its $FILE_NAME timestamps reflect the actual installation period. The analyst suspects timestomping. Which conclusion is most defensible based on NTFS timestamp behavior?
Hard19During a Windows 10 intrusion investigation, an analyst uses fls on a raw NTFS image and observes that for a suspicious executable, the $FILE_NAME creation timestamp is 2023-08-10 14:22:01, while the $STANDARD_INFORMATION creation timestamp is 2023-08-10 14:22:01 as well, but the $STANDARD_INFORMATION modified timestamp is 2023-08-10 14:22:01 and the $FILE_NAME modified timestamp is 2023-08-10 14:22:01. However, the $MFT record header's last modification time (the MFT entry itself) is 2023-08-10 14:25:33. What is the most likely explanation for the discrepancy between the MFT record modification time and the file's timestamps?
Medium20During an investigation of an ext4 file system, an analyst runs `fls -r -m /` and `mactime` to build a body file. The analyst observes that many deleted files show a dtime in the body file, but the mactime timeline places those dtime entries at the time the file was deleted. A colleague claims that dtime in ext4 always represents the time the inode was last modified. Which statement correctly describes ext4 dtime behavior in this timeline context?
HardOther domains
All GCFA exam domains
Frequently asked questions
- What does the File System Timeline Artifact Analysis domain cover on the GCFA exam?
- A candidate must interpret MACB timestamp combinations across NTFS and ext4 artifacts and explain what each change indicates. The most important thing is distinguishing legitimate system updates from anti-forensic manipulation by cross-checking $STANDARD_INFORMATION against $FILE_NAME timestamps and inode metadata.
- How many questions are in this domain?
- This page lists all 20 File System Timeline Artifact Analysis questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only File System Timeline Artifact Analysis questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.