A forensic analyst is examining an NTFS volume and needs to identify which artifacts can provide evidence of file deletion or file system changes that occurred after a file was removed. Which TWO of the following NTFS artifacts are most directly useful for this purpose? (Choose two.)
The USN change journal records events with reason flags, including FILE_DELETE, which indicates a file was deleted. Each record includes the file reference number and timestamp, allowing analysts to correlate deletion events with other activity. This directly supports determining when and possibly how a file was removed.
Why this answer
$Bitmap tracks cluster allocation and can show clusters freed by deletion, while $UsnJrnl:$J logs file system events including FILE_DELETE with timestamps and file references. Together they help identify deleted files and the timing of deletions, making them the most directly useful artifacts among the listed metadata files.
Exam trap
The trap here is confusing general NTFS metadata files with event-logging artifacts, when only $Bitmap and the USN journal provide direct evidence of deletion and post-deletion changes.