GCFA · domain
NTFS Artifact Analysis
This domain covers how NTFS stores metadata and change history across $MFT, $STANDARD_INFORMATION, $FILE_NAME, $LogFile, and $UsnJrnl. GCFA questions present imaging or live-response scenarios and ask you to identify which artifact proves a rename, creation, deletion, or timestamp inconsistency, and to reason about record ordering and journal retention.
Focused practice
Practice NTFS Artifact Analysis questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about NTFS Artifact Analysis
Be able to map a rename or deletion to the correct NTFS artifact and justify it with reason codes and timestamps. The single most important thing: know when to trust $UsnJrnl versus $LogFile versus $MFT metadata, and never rely on one timestamp alone.
Interpreting $STANDARD_INFORMATION versus $FILE_NAME timestamp pairs in $MFT records
Using $UsnJrnl reason codes to prove file rename, creation, and deletion events
Distinguishing $LogFile transactional metadata from $UsnJrnl long-term change records
Correlating MFT record numbers, sequence numbers, and out-of-order profile folders
Watch out for
Common NTFS Artifact Analysis exam traps
- ▸Assuming $STANDARD_INFORMATION timestamps are authoritative; $FILE_NAME timestamps often preserve earlier creation times and can reveal timestomping.
- ▸Treating $UsnJrnl as permanent; it is sparse and can be overwritten or deleted, so absence of records is not proof of no activity.
- ▸Confusing $LogFile with $UsnJrnl; $LogFile is a circular transaction log for crash recovery, not a long-term user activity journal.
Question index
All NTFS Artifact Analysis questions (37)
Click any question to see the full explanation, or start a practice session above.
A forensic analyst is examining an NTFS volume and needs to identify which artifacts can provide evidence of file deletion or file system changes that occurred after a file was removed. Which TWO of the following NTFS artifacts are most directly useful for this purpose? (Choose two.)
Medium2A forensic analyst is investigating a system where a user is suspected of using a tool to hide files by manipulating NTFS metadata. The analyst finds an MFT entry with a $FILE_NAME attribute that has a namespace value of 2 (POSIX) and a $STANDARD_INFORMATION attribute with timestamps that are inconsistent with the file's $UsnJrnl records. Which conclusion is most appropriate regarding the file's naming and timestamp artifacts?
Hard3What is the consequence of a file name being stored in the $FILE_NAME attribute but not in the $INDEX_ROOT of its parent directory?
Medium4A forensic analyst is reviewing a Windows 10 workstation suspected of unauthorized data staging. While parsing the Master File Table with a commercial forensic suite, the analyst observes that a suspicious .zip file's $STANDARD_INFORMATION timestamps differ from its $FILE_NAME timestamps by more than six months, and the $FILE_NAME timestamps are older. Which conclusion is most consistent with this artifact pattern?
Medium5Which NTFS metadata attribute is responsible for storing Security Descriptors (ACLs)?
Medium6What does a non-resident $DATA attribute indicate in an NTFS MFT record?
Medium7Which NTFS attribute would an investigator primarily examine to determine the parent directory of a specific file?
Easy8An investigator is examining an NTFS volume from a system that was abruptly powered off during a malware installation. The analyst observes that the MFT contains a file record for a suspicious executable with a valid $DATA attribute, but the file is not visible in the directory index. Which NTFS artifact should the analyst examine to determine whether the file record was orphaned due to an interrupted transaction?
Hard9Which NTFS metadata file serves as the index for all files and directories on the volume?
Easy10What is the primary purpose of the $LogFile in NTFS?
Medium11Which NTFS master file table (MFT) record contains metadata about the MFT itself?
Easy12An examiner is analyzing an NTFS volume from a Windows Server 2016 system that was abruptly powered off during a security incident. The examiner wants to determine recent file system changes that may not have been flushed to the $MFT. Which two NTFS artifacts should the examiner prioritize to reconstruct recent metadata operations? (Choose two.)
Hard13An analyst is examining an NTFS volume from a Windows Server 2019 system that was used as a file server. A file critical to the investigation is missing from the directory listing, but the analyst suspects the file was recently deleted and its MFT entry has not been overwritten. Which NTFS artifact should the analyst examine to recover the file's full path and name if the MFT entry is still intact?
Hard14What is the primary function of the $ATTRIBUTE_LIST attribute in an MFT entry?
Hard15You are analyzing an NTFS volume and need to determine the original path and name of a file that has been moved to a different directory. The file's MFT entry contains multiple $FILE_NAME attributes. Which two of the following statements about $FILE_NAME attributes are correct? (Choose two.)
Hard16What is the significance of the $LogFile in NTFS when performing an investigation on a system that experienced a sudden power loss?
Medium17What is the primary role of the $MFTMirr file in NTFS?
Easy18An analyst is examining a Windows 10 system where a user deleted several files containing sensitive data. The analyst needs to recover the file content and determines that the $DATA attribute of the MFT record for one deleted file is resident. What does this indicate about the file's data and its recoverability?
Medium19During an investigation, you recover a deleted file from an NTFS volume. The MFT entry for the file shows that the $DATA attribute is non-resident, and the data runs are still intact. However, the $BITMAP attribute of the MFT indicates that the MFT entry is marked as unallocated. What is the most accurate conclusion about the recoverability of the file's content?
Hard20An analyst is examining an NTFS volume and wants to identify the MFT entry for a specific file named 'report.docx'. The analyst knows the file's path but needs to locate its MFT record number to examine its attributes. Which NTFS metadata file should the analyst consult to map the file path to its MFT record number?
Easy21During a forensic analysis, you encounter a file with a 'resident' $DATA attribute. What does this mean for your data recovery process?
Medium22A forensic analyst is reviewing an NTFS volume and notices that a particular file has an $ATTRIBUTE_LIST attribute in its MFT record. What does the presence of this attribute indicate about the file?
Easy23An investigator is analyzing an NTFS volume from a compromised server. A file named 'payroll.xlsx' appears in the directory listing, but the MFT record for that filename shows a zero-length $DATA attribute and no $OBJECT_ID. A separate MFT record with a different record number contains the same $FILE_NAME value, a large non-resident $DATA attribute, and an $OBJECT_ID. Which NTFS artifact best explains the presence of two MFT records referencing the same filename?
Hard24An analyst is examining an NTFS volume and finds a file named 'confidential.docx' in a directory. The file's MFT record shows that the $DATA attribute is resident. What does this indicate about the file's data storage, and what is the primary forensic implication?
Easy25An analyst is examining the USN Journal. What is the primary purpose of this file in the context of NTFS forensic analysis?
Medium26A forensic analyst is examining an NTFS volume and needs to determine whether a specific file was recently deleted and whether its data clusters have been reallocated. The analyst has access to the MFT, the $Bitmap metadata file, and the $UsnJrnl. Which two artifacts should the analyst correlate to confirm that the file's MFT record is unallocated and that its clusters are now marked as free? (Choose two.)
Medium27A forensic analyst is examining an NTFS volume and finds that a directory's $I30 index entries are present in the $INDEX_ROOT, but the $INDEX_ALLOCATION attribute is non-resident and points to INDX records. The analyst needs to determine whether a deleted file once existed in that directory. Which artifact should the analyst examine to find residual filename entries that may reference the deleted file?
Medium28Which attribute is used to store the location and length of file data runs in an NTFS MFT record?
Hard29A forensic analyst is reviewing an NTFS volume and notices that a particular MFT record has an $ATTRIBUTE_LIST attribute. The analyst wants to understand why this attribute is present. Which of the following best describes the purpose of the $ATTRIBUTE_LIST attribute in an MFT record?
Easy30An analyst is examining an NTFS volume and finds that a file's $DATA attribute is non-resident, but the file size reported by the operating system is 0 bytes. The analyst suspects the file may have been involved in a data hiding technique. Which of the following is the most likely explanation for this discrepancy?
Hard31A first responder is collecting volatile and non-volatile data from a running Windows Server 2019 system. The investigator needs to determine which user or process most recently renamed a specific file on an NTFS volume, but the $STANDARD_INFORMATION timestamps show only a modification time. Which NTFS artifact should the investigator query to find rename events that record the previous filename?
Easy32What is the primary advantage of the $UsnJrnl over the $LogFile for long-term forensic analysis?
Medium33An investigator is analyzing an NTFS volume and finds that a file's $DATA attribute is non-resident and its data runs point to clusters that are currently allocated to a different file. The file's size is 10 KB. What is the most likely explanation for this situation?
Hard34An examiner images a Windows 10 workstation and notices that several user profile folders are out of order in the \$MFT when sorted by MFT record number, yet the $STANDARD_INFORMATION timestamps are consistent. The examiner suspects that entries were reordered or that records were freed and reused. Which NTFS artifact best supports determining whether MFT record numbers have been reassigned to different files over time?
Medium35An analyst discovers a file with a non-zero size but no data in the $DATA attribute. Where is the file content likely located?
Medium36A forensic analyst is reviewing an NTFS volume from a Windows 10 workstation. The analyst finds an MFT entry whose $STANDARD_INFORMATION attribute contains four timestamps that are all set to a date three years in the past, but the corresponding $FILE_NAME attribute timestamps show dates within the past week. The file's content matches a recently created document. Which conclusion is most strongly supported by this artifact discrepancy?
Medium37An analyst is examining an NTFS volume and finds that a file's $DATA attribute is resident. The file size is 800 bytes. The analyst attempts to recover the file content using a tool that only reads the data runs from the MFT record. What will be the outcome of this recovery attempt?
HardOther domains
All GCFA exam domains
Frequently asked questions
- What does the NTFS Artifact Analysis domain cover on the GCFA exam?
- Be able to map a rename or deletion to the correct NTFS artifact and justify it with reason codes and timestamps. The single most important thing: know when to trust $UsnJrnl versus $LogFile versus $MFT metadata, and never rely on one timestamp alone.
- How many questions are in this domain?
- This page lists all 37 NTFS Artifact Analysis questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only NTFS Artifact Analysis questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.