GCFA · domain
Windows Artifact Analysis
This domain covers forensic examination of NTFS metadata, registry-backed execution artifacts, and shell item databases on Windows hosts. GCFA tests whether you can interpret $MFT records, $STANDARD_INFORMATION versus $FILE_NAME timestamps, ShimCache/AmCache entries, UserAssist, and Jump Lists to reconstruct file creation, execution, and user activity from an acquired image.
Focused practice
Practice Windows Artifact Analysis questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Windows Artifact Analysis
Be able to locate and interpret NTFS metadata, registry execution artifacts, and Jump Lists on a Windows image. The most important thing is distinguishing evidence of file presence from evidence of actual execution, and knowing which timestamps and artifacts can be trusted.
Interpreting $MFT record attributes, resident vs non-resident data, and $STANDARD_INFORMATION versus $FILE_NAME timestamps
Using ShimCache (AppCompatCache) and AmCache to infer executable presence versus confirmed execution
Parsing Jump Lists in AutomaticDestinations and CustomDestinations, including .automaticDestinations-ms OLE structure
Examining NTFS attributes such as hidden, system, and alternate data streams used to conceal files
Watch out for
Common Windows Artifact Analysis exam traps
- ▸Treating a ShimCache entry as proof of execution; it only shows the file was seen by the system, not necessarily run.
- ▸Assuming $STANDARD_INFORMATION timestamps are reliable; they are easily modified, unlike $FILE_NAME timestamps.
- ▸Confusing Jump List folders or extensions, such as mixing AutomaticDestinations with CustomDestinations or wrong file suffixes.
Question index
All Windows Artifact Analysis questions (28)
Click any question to see the full explanation, or start a practice session above.
An analyst is reviewing a Windows 10 system and wants to determine the last time a user accessed a specific file. The analyst examines the file's NTFS standard information attributes and finds that the last access time is not updated. What is the most likely reason for this?
Easy2An analyst is investigating a Windows 10 system where an attacker allegedly used a remote access tool (RAT) that persists by modifying the Image File Execution Options (IFEO) registry key. The analyst wants to identify which executable was hijacked. Which registry location should the analyst examine to find the Debugger value that redirects execution?
Medium3An analyst is examining a Windows 10 workstation that is suspected of having a malicious service installed for persistence. The analyst wants to determine the original path of the service executable and the account it runs under. Which registry location should the analyst examine to find this information?
Medium4An investigator is analyzing a Windows 10 system where an attacker allegedly used a PowerShell script to download and execute a malicious payload. The investigator wants to determine the exact PowerShell commands that were executed. Which Windows artifact should the investigator examine to find this information?
Hard5During a compromise investigation, an analyst reviews Windows Event Logs and observes that Security Event ID 4688 entries are present, but the Process Command Line field is empty for all of them. The system is running Windows 10 Enterprise. What is the most likely reason for the missing command line data?
Medium6An analyst is examining a Windows 10 system and finds a suspicious file in the Recycle Bin. The analyst wants to determine the original path of the file before it was deleted. Which artifact should the analyst examine to find the original file path and deletion time?
Medium7An analyst is examining a Windows 10 system to determine if a specific USB device was connected. The analyst has already checked the registry and found no trace in USBSTOR. Which TWO additional artifacts should the analyst examine to corroborate USB device connection? (Choose two.)
Medium8When analyzing the 'TypedPaths' registry key, what type of user activity is being reviewed?
Medium9An analyst is investigating a Windows 10 system and discovers that a user's NTUSER.DAT registry hive contains a key named 'RecentDocs' with numerous entries. What is the primary forensic significance of this artifact?
Hard10During a forensic examination of a Windows 10 workstation, an analyst needs to determine which user account was interactively logged on at a specific date and time. The system is powered off and only the disk image is available. Which artifact should the analyst examine to find the most reliable record of interactive logon sessions, including logon type and timestamp?
Medium11A forensic analyst is examining a Windows 10 system and wants to determine which USB storage devices have been connected to the machine. The analyst has access to the registry. Which registry key should the analyst examine to find a list of USB devices that have been connected, including vendor and product IDs?
Easy12Which artifact is the most reliable for determining if an external USB mass storage device was mounted on a system, even if the device is no longer present?
Medium13An analyst discovers a suspicious executable in the C:\Users\Public folder. To determine if the file was executed, the analyst examines the Shimcache. Which behavior is characteristic of the Shimcache artifact?
Medium14An analyst is investigating a Windows 10 system for evidence of lateral movement. The analyst suspects that an attacker used PsExec to remotely execute commands on the system. Which TWO artifacts should the analyst examine to corroborate this activity? (Choose two.)
Medium15Which registry hive contains the 'UserAssist' key, and what is its primary forensic value?
Medium16An analyst is investigating a Windows 10 system and finds a suspicious shortcut file in a user's Recent folder. The analyst wants to determine the full path of the target file and any command-line arguments used when the shortcut was created. Which artifact should the analyst examine?
Medium17An analyst discovers a file on a system that appears to be a 'hidden' executable. Which attribute of the NTFS file system, if modified, is a common indicator of a user attempting to conceal a file from standard Explorer views?
Medium18An investigator is analyzing the Windows Event Logs and finds Event ID 4697. What is the primary significance of this event in the context of forensic analysis?
Hard19What is the primary function of the ShellBags artifact in a Windows forensic investigation?
Medium20An analyst is examining a Windows 10 system to determine if a specific user account was used to access files on a remote share. Which two artifacts would provide the most direct evidence of this activity? (Choose two.)
Hard21Which of the following describes the correct function of the $MFT (Master File Table) in an NTFS-formatted Windows volume?
Medium22An analyst is examining a Windows 10 system and finds that the ShimCache (AppCompatCache) contains an entry for a malicious executable. The analyst wants to determine whether the executable was actually executed on the system. Which additional artifact should the analyst examine to confirm execution?
Hard23When reviewing Jump Lists on a Windows system, which file extension is commonly associated with the 'AutomaticDestinations' folder?
Medium24An investigator is examining a Windows 10 system and finds a prefetch file named 'POWERSHELL.EXE-12345678.pf' in the C:\Windows\Prefetch folder. What is the primary forensic value of this artifact?
Easy25An analyst is examining a Windows 10 host and finds that a suspicious process was launched shortly after a user logged on. To determine the exact time the process was created and capture its parent-child relationship, which artifact should the analyst prioritize?
Medium26An analyst is reviewing a Windows 10 endpoint and finds that a scheduled task was created to run a PowerShell script at logon. The task was likely created by an attacker to maintain persistence. Which artifact should the analyst examine to determine the exact time the task was registered and the user account that created it?
Medium27When analyzing the Windows Registry, what is the primary purpose of the 'SAM' hive?
Medium28During an intrusion investigation, an analyst needs to determine the exact moment a malicious service was installed on a Windows 10 host. The attacker deleted the service's executable and cleared the System event log. Which artifact should the analyst examine to recover the service installation timestamp?
MediumOther domains
All GCFA exam domains
Frequently asked questions
- What does the Windows Artifact Analysis domain cover on the GCFA exam?
- Be able to locate and interpret NTFS metadata, registry execution artifacts, and Jump Lists on a Windows image. The most important thing is distinguishing evidence of file presence from evidence of actual execution, and knowing which timestamps and artifacts can be trusted.
- How many questions are in this domain?
- This page lists all 28 Windows Artifact Analysis questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Windows Artifact Analysis questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.