GCFA · domain
Introduction to File System Timeline Forensics
This domain covers building and interpreting file system timelines for forensics, focusing on NTFS and ext4 metadata, MACB timestamp semantics, and tools like log2timeline, Plaso, and The Sleuth Kit. Questions test whether you can extract, filter, and reason about timestamps rather than merely generate a timeline.
Focused practice
Practice Introduction to File System Timeline Forensics questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Introduction to File System Timeline Forensics
You must be able to build a MACB file system timeline and correctly interpret each timestamp's meaning and reliability. The most important thing is knowing which timestamps are trustworthy versus user-modifiable, and filtering super-timeline output before drawing conclusions.
Extracting MACB timestamps from NTFS $STANDARD_INFORMATION and $FILE_NAME attributes
Using log2timeline/Plaso to build super-timelines and filter output for relevance
Interpreting ext4 timestamps via The Sleuth Kit fls and istat output
Recognizing time skew, clock drift, and timezone effects in timeline data
Watch out for
Common Introduction to File System Timeline Forensics exam traps
- ▸Assuming $STANDARD_INFORMATION timestamps are reliable; they are easily modified by user-mode tools and can be forged.
- ▸Treating every access time as proof of user interaction, ignoring atime update policies and filesystem mount options.
- ▸Forgetting to normalize timezones and clock skew, producing timelines with misordered or misleading events.
Question index
All Introduction to File System Timeline Forensics questions (31)
Click any question to see the full explanation, or start a practice session above.
An investigator is analyzing a Windows 10 system and needs to correlate file system timestamps with other artifacts to build a comprehensive timeline. Which two of the following Windows artifacts can provide additional temporal context when combined with NTFS timestamps? (Choose two.)
Hard2Which of the following describes the 'MAC' in MACB times during timeline analysis?
Easy3A forensic analyst is building a timeline from an NTFS volume and wants to include the time when a file's metadata was last changed, such as permission modifications. Which timestamp should the analyst focus on to capture this event?
Easy4An analyst acquires a forensic image of a Windows 10 NTFS volume using a write blocker and now needs to build a file system timeline. The analyst wants to include the $STANDARD_INFORMATION timestamps but also wants to detect timestomping by comparing them with the $FILE_NAME timestamps. Which tool should the analyst use to extract both timestamp sets from the MFT and generate a bodyfile for timeline creation?
Easy5An analyst is examining an NTFS volume and notices that a file's MFT entry shows a modification time earlier than its creation time. What is the most likely cause for this anomaly?
Medium6An investigator is analyzing an NTFS volume from a Windows Server 2016 system that was recently compromised. The attacker used a tool to modify file timestamps to evade detection. The investigator notices that the $STANDARD_INFORMATION timestamps for a suspicious executable are all set to 2018-01-01, while the $FILE_NAME timestamps remain at 2021-06-15. The $MFT entry number is 12345. What is the most accurate conclusion regarding the timestamp manipulation?
Hard7When performing timeline analysis on a Linux system, which file is the most critical to examine to reconstruct user login and logout history?
Medium8A forensic analyst is examining a Linux ext4 file system and wants to determine when a file's metadata (such as permissions or ownership) was last changed. Which timestamp should they examine?
Easy9An investigator notices that a file's 'Birth' time is later than its 'Modification' time. What is the most likely forensic explanation for this phenomenon?
Medium10During a forensic investigation of a Windows 10 workstation, an analyst reviews the NTFS Master File Table (MFT) and notices that the $STANDARD_INFORMATION timestamps for a suspicious file are all dated 2023-08-15, but the $FILE_NAME timestamps are dated 2024-01-20. The file is located in C:\Users\Public\Downloads. Which of the following best explains this discrepancy?
Medium11Why might an analyst prefer using 'Super-Timeline' creation tools, such as log2timeline, over manual collection of file system timestamps?
Medium12A forensic analyst is creating a timeline from a Windows 10 workstation using fls and mactime from The Sleuth Kit. The analyst notices that the bodyfile contains entries with timestamps that appear to be off by several hours compared to the wall-clock time the incident was reported. The system is known to be set to UTC in the BIOS. Which action best ensures the timeline is correctly aligned for reporting?
Medium13During a forensic investigation of a Windows 10 system, an analyst observes that a file's $STANDARD_INFORMATION creation timestamp is 2020-01-01 10:00:00, while its $FILE_NAME creation timestamp is 2020-01-01 10:00:05. The system time zone is UTC-5. The analyst also notes that the file's $STANDARD_INFORMATION modification timestamp is 2020-01-01 10:00:00. What is the most likely explanation for the 5-second difference between the creation timestamps?
Hard14During a forensic examination of an NTFS volume, an analyst notices that a file's $STANDARD_INFORMATION timestamps show a modification time of 2023-04-01 10:00:00, but the $FILE_NAME timestamps show a modification time of 2023-03-15 14:30:00. The file is not a system file and has not been renamed. What is the most likely explanation for this discrepancy?
Medium15An investigator is preparing to analyze a Windows 10 workstation's NTFS volume using a forensic tool that reads the master file table (MFT) directly. The goal is to build a timeline that includes timestamps for files that were deleted before the acquisition. Which artifact should the investigator primarily rely on to recover timestamps for deleted files?
Easy16A forensic analyst is building a file system timeline from an NTFS volume and wants to ensure it includes reliable evidence of file creation and deletion events. Which two artifacts should the analyst prioritize to capture these events? (Choose two.)
Medium17During a timeline review of an NTFS volume, an analyst observes that a file's $STANDARD_INFORMATION modification time is several days earlier than its $FILE_NAME modification time, and the $STANDARD_INFORMATION creation time is also earlier than the $FILE_NAME creation time. The file is a suspected malware dropper. Which conclusion is best supported by this pattern?
Hard18What is the primary function of the $LogFile in NTFS when reconstructing a timeline?
Medium19Which of these is the primary limitation of using a file system 'Birth' time as a definitive event marker?
Medium20An investigator is analyzing a Linux ext4 file system and needs to determine when a file's content was last modified. The file's inode contains ctime, mtime, and atime fields. Which timestamp should the investigator use to answer this specific question?
Medium21An analyst is creating a timeline from a forensic image of a Windows 7 system using The Sleuth Kit's fls and mactime tools. The analyst notices that the timeline includes entries for files that no longer exist on the volume. Which NTFS artifact is most likely responsible for these entries, and how should the analyst interpret them?
Easy22During a forensic investigation of an NTFS volume, an analyst notices that the $MFT record for a suspicious executable shows a modified time earlier than its creation time. What does this specific anomaly typically indicate?
Medium23A forensic analyst is examining an NTFS volume and wants to identify potential timestomping. Which TWO artifacts should the analyst compare to detect inconsistencies in file timestamps? (Choose two.)
Hard24An investigator is building a file system timeline for an NTFS volume from a Windows 10 workstation. The user claims a file was copied to an external drive at 14:00, but the file's NTFS Standard Information Attribute shows only a modification timestamp of 13:45. Which NTFS artifact should the investigator examine to determine when the filename was actually created or renamed on the volume?
Medium25An analyst is building a file system timeline from an NTFS volume and is deciding which timestamps to extract from the $STANDARD_INFORMATION attribute. A colleague suggests that the four timestamps in $STANDARD_INFORMATION are the only relevant times. Which statement correctly describes the relationship between $STANDARD_INFORMATION and $FILE_NAME timestamps?
Easy26An investigator is adding NTFS USN change journal records to a file system timeline on a Windows 10 workstation. The journal was captured live with fsutil usn readjournal and shows a record with Reason value 0x00000100 (DATA_OVERWRITE) for a user document. The investigator wants to determine whether the file content was actually altered at that moment. Which statement best describes what the USN record establishes?
Medium27When creating a super-timeline using tools like log2timeline, why is it critical to filter the output data?
Medium28Why should a forensic analyst avoid using the 'Last Accessed' time as the primary indicator for a file's usage?
Easy29In the context of forensic timeline analysis, what does the term 'Time Skew' refer to?
Easy30An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?
Hard31A forensic analyst is using a tool to generate a file system timeline from an NTFS volume. The tool outputs timestamps with nanosecond precision, but the analyst knows that NTFS stores timestamps with 100-nanosecond resolution. What is the most likely reason for the discrepancy?
EasyOther domains
All GCFA exam domains
Frequently asked questions
- What does the Introduction to File System Timeline Forensics domain cover on the GCFA exam?
- You must be able to build a MACB file system timeline and correctly interpret each timestamp's meaning and reliability. The most important thing is knowing which timestamps are trustworthy versus user-modifiable, and filtering super-timeline output before drawing conclusions.
- How many questions are in this domain?
- This page lists all 31 Introduction to File System Timeline Forensics questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Introduction to File System Timeline Forensics questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.