Courseiva

GCFA · domain

NTFS Artifact Analysis

This domain covers how NTFS stores metadata and change history across $MFT, $STANDARD_INFORMATION, $FILE_NAME, $LogFile, and $UsnJrnl. GCFA questions present imaging or live-response scenarios and ask you to identify which artifact proves a rename, creation, deletion, or timestamp inconsistency, and to reason about record ordering and journal retention.

37 questions9 easy16 medium12 hard

Focused practice

Practice NTFS Artifact Analysis questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about NTFS Artifact Analysis

Be able to map a rename or deletion to the correct NTFS artifact and justify it with reason codes and timestamps. The single most important thing: know when to trust $UsnJrnl versus $LogFile versus $MFT metadata, and never rely on one timestamp alone.

Interpreting $STANDARD_INFORMATION versus $FILE_NAME timestamp pairs in $MFT records

Using $UsnJrnl reason codes to prove file rename, creation, and deletion events

Distinguishing $LogFile transactional metadata from $UsnJrnl long-term change records

Correlating MFT record numbers, sequence numbers, and out-of-order profile folders

Watch out for

Common NTFS Artifact Analysis exam traps

  • ▸Assuming $STANDARD_INFORMATION timestamps are authoritative; $FILE_NAME timestamps often preserve earlier creation times and can reveal timestomping.
  • ▸Treating $UsnJrnl as permanent; it is sparse and can be overwritten or deleted, so absence of records is not proof of no activity.
  • ▸Confusing $LogFile with $UsnJrnl; $LogFile is a circular transaction log for crash recovery, not a long-term user activity journal.

Question index

All NTFS Artifact Analysis questions (37)

Click any question to see the full explanation, or start a practice session above.

1

A forensic analyst is examining an NTFS volume and needs to identify which artifacts can provide evidence of file deletion or file system changes that occurred after a file was removed. Which TWO of the following NTFS artifacts are most directly useful for this purpose? (Choose two.)

Medium
2

A forensic analyst is investigating a system where a user is suspected of using a tool to hide files by manipulating NTFS metadata. The analyst finds an MFT entry with a $FILE_NAME attribute that has a namespace value of 2 (POSIX) and a $STANDARD_INFORMATION attribute with timestamps that are inconsistent with the file's $UsnJrnl records. Which conclusion is most appropriate regarding the file's naming and timestamp artifacts?

Hard
3

What is the consequence of a file name being stored in the $FILE_NAME attribute but not in the $INDEX_ROOT of its parent directory?

Medium
4

A forensic analyst is reviewing a Windows 10 workstation suspected of unauthorized data staging. While parsing the Master File Table with a commercial forensic suite, the analyst observes that a suspicious .zip file's $STANDARD_INFORMATION timestamps differ from its $FILE_NAME timestamps by more than six months, and the $FILE_NAME timestamps are older. Which conclusion is most consistent with this artifact pattern?

Medium
5

Which NTFS metadata attribute is responsible for storing Security Descriptors (ACLs)?

Medium
6

What does a non-resident $DATA attribute indicate in an NTFS MFT record?

Medium
7

Which NTFS attribute would an investigator primarily examine to determine the parent directory of a specific file?

Easy
8

An investigator is examining an NTFS volume from a system that was abruptly powered off during a malware installation. The analyst observes that the MFT contains a file record for a suspicious executable with a valid $DATA attribute, but the file is not visible in the directory index. Which NTFS artifact should the analyst examine to determine whether the file record was orphaned due to an interrupted transaction?

Hard
9

Which NTFS metadata file serves as the index for all files and directories on the volume?

Easy
10

What is the primary purpose of the $LogFile in NTFS?

Medium
11

Which NTFS master file table (MFT) record contains metadata about the MFT itself?

Easy
12

An examiner is analyzing an NTFS volume from a Windows Server 2016 system that was abruptly powered off during a security incident. The examiner wants to determine recent file system changes that may not have been flushed to the $MFT. Which two NTFS artifacts should the examiner prioritize to reconstruct recent metadata operations? (Choose two.)

Hard
13

An analyst is examining an NTFS volume from a Windows Server 2019 system that was used as a file server. A file critical to the investigation is missing from the directory listing, but the analyst suspects the file was recently deleted and its MFT entry has not been overwritten. Which NTFS artifact should the analyst examine to recover the file's full path and name if the MFT entry is still intact?

Hard
14

What is the primary function of the $ATTRIBUTE_LIST attribute in an MFT entry?

Hard
15

You are analyzing an NTFS volume and need to determine the original path and name of a file that has been moved to a different directory. The file's MFT entry contains multiple $FILE_NAME attributes. Which two of the following statements about $FILE_NAME attributes are correct? (Choose two.)

Hard
16

What is the significance of the $LogFile in NTFS when performing an investigation on a system that experienced a sudden power loss?

Medium
17

What is the primary role of the $MFTMirr file in NTFS?

Easy
18

An analyst is examining a Windows 10 system where a user deleted several files containing sensitive data. The analyst needs to recover the file content and determines that the $DATA attribute of the MFT record for one deleted file is resident. What does this indicate about the file's data and its recoverability?

Medium
19

During an investigation, you recover a deleted file from an NTFS volume. The MFT entry for the file shows that the $DATA attribute is non-resident, and the data runs are still intact. However, the $BITMAP attribute of the MFT indicates that the MFT entry is marked as unallocated. What is the most accurate conclusion about the recoverability of the file's content?

Hard
20

An analyst is examining an NTFS volume and wants to identify the MFT entry for a specific file named 'report.docx'. The analyst knows the file's path but needs to locate its MFT record number to examine its attributes. Which NTFS metadata file should the analyst consult to map the file path to its MFT record number?

Easy
21

During a forensic analysis, you encounter a file with a 'resident' $DATA attribute. What does this mean for your data recovery process?

Medium
22

A forensic analyst is reviewing an NTFS volume and notices that a particular file has an $ATTRIBUTE_LIST attribute in its MFT record. What does the presence of this attribute indicate about the file?

Easy
23

An investigator is analyzing an NTFS volume from a compromised server. A file named 'payroll.xlsx' appears in the directory listing, but the MFT record for that filename shows a zero-length $DATA attribute and no $OBJECT_ID. A separate MFT record with a different record number contains the same $FILE_NAME value, a large non-resident $DATA attribute, and an $OBJECT_ID. Which NTFS artifact best explains the presence of two MFT records referencing the same filename?

Hard
24

An analyst is examining an NTFS volume and finds a file named 'confidential.docx' in a directory. The file's MFT record shows that the $DATA attribute is resident. What does this indicate about the file's data storage, and what is the primary forensic implication?

Easy
25

An analyst is examining the USN Journal. What is the primary purpose of this file in the context of NTFS forensic analysis?

Medium
26

A forensic analyst is examining an NTFS volume and needs to determine whether a specific file was recently deleted and whether its data clusters have been reallocated. The analyst has access to the MFT, the $Bitmap metadata file, and the $UsnJrnl. Which two artifacts should the analyst correlate to confirm that the file's MFT record is unallocated and that its clusters are now marked as free? (Choose two.)

Medium
27

A forensic analyst is examining an NTFS volume and finds that a directory's $I30 index entries are present in the $INDEX_ROOT, but the $INDEX_ALLOCATION attribute is non-resident and points to INDX records. The analyst needs to determine whether a deleted file once existed in that directory. Which artifact should the analyst examine to find residual filename entries that may reference the deleted file?

Medium
28

Which attribute is used to store the location and length of file data runs in an NTFS MFT record?

Hard
29

A forensic analyst is reviewing an NTFS volume and notices that a particular MFT record has an $ATTRIBUTE_LIST attribute. The analyst wants to understand why this attribute is present. Which of the following best describes the purpose of the $ATTRIBUTE_LIST attribute in an MFT record?

Easy
30

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is non-resident, but the file size reported by the operating system is 0 bytes. The analyst suspects the file may have been involved in a data hiding technique. Which of the following is the most likely explanation for this discrepancy?

Hard
31

A first responder is collecting volatile and non-volatile data from a running Windows Server 2019 system. The investigator needs to determine which user or process most recently renamed a specific file on an NTFS volume, but the $STANDARD_INFORMATION timestamps show only a modification time. Which NTFS artifact should the investigator query to find rename events that record the previous filename?

Easy
32

What is the primary advantage of the $UsnJrnl over the $LogFile for long-term forensic analysis?

Medium
33

An investigator is analyzing an NTFS volume and finds that a file's $DATA attribute is non-resident and its data runs point to clusters that are currently allocated to a different file. The file's size is 10 KB. What is the most likely explanation for this situation?

Hard
34

An examiner images a Windows 10 workstation and notices that several user profile folders are out of order in the \$MFT when sorted by MFT record number, yet the $STANDARD_INFORMATION timestamps are consistent. The examiner suspects that entries were reordered or that records were freed and reused. Which NTFS artifact best supports determining whether MFT record numbers have been reassigned to different files over time?

Medium
35

An analyst discovers a file with a non-zero size but no data in the $DATA attribute. Where is the file content likely located?

Medium
36

A forensic analyst is reviewing an NTFS volume from a Windows 10 workstation. The analyst finds an MFT entry whose $STANDARD_INFORMATION attribute contains four timestamps that are all set to a date three years in the past, but the corresponding $FILE_NAME attribute timestamps show dates within the past week. The file's content matches a recently created document. Which conclusion is most strongly supported by this artifact discrepancy?

Medium
37

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is resident. The file size is 800 bytes. The analyst attempts to recover the file content using a tool that only reads the data runs from the MFT record. What will be the outcome of this recovery attempt?

Hard

Frequently asked questions

What does the NTFS Artifact Analysis domain cover on the GCFA exam?
Be able to map a rename or deletion to the correct NTFS artifact and justify it with reason codes and timestamps. The single most important thing: know when to trust $UsnJrnl versus $LogFile versus $MFT metadata, and never rely on one timestamp alone.
How many questions are in this domain?
This page lists all 37 NTFS Artifact Analysis questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only NTFS Artifact Analysis questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcfa GIAC-GCFA ntfs artifact analysis Practice Questions