Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

During a timeline review of an NTFS volume, an analyst observes that a file's $STANDARD_INFORMATION modification time is several days earlier than its $FILE_NAME modification time, and the $STANDARD_INFORMATION creation time is also earlier than the $FILE_NAME creation time. The file is a suspected malware dropper. Which conclusion is best supported by this pattern?

⚠ Common exam trap

The trap here is jumping to timestomping whenever the two attribute timestamp sets disagree, without considering legitimate rename or move operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file was likely moved or renamed after its last content modification, causing the $FILE_NAME timestamps to update while $STANDARD_INFORMATION times remained older.

When a file is moved or renamed within an NTFS volume, the $FILE_NAME attribute timestamps are updated to the time of the operation, while $STANDARD_INFORMATION timestamps may remain unchanged. This produces a pattern where $FILE_NAME times are newer than $STANDARD_INFORMATION times. While timestomping can also create discrepancies, it typically makes $STANDARD_INFORMATION appear older, and without additional indicators the move or rename explanation is better supported by the specific pattern observed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The file was likely moved or renamed after its last content modification, causing the $FILE_NAME timestamps to update while $STANDARD_INFORMATION times remained older.

    Why this is correct

    A move or rename within the same volume updates the $FILE_NAME timestamps but does not necessarily update $STANDARD_INFORMATION. The observed gap where $FILE_NAME times are newer than $STANDARD_INFORMATION times is consistent with such an operation and provides a plausible timeline sequence.

  • ✗

    The file's timestamps were definitely manipulated with a timestomping tool that altered $STANDARD_INFORMATION.

    Why it's wrong here

    Timestomping typically affects $STANDARD_INFORMATION and can make it appear older, but the pattern here can also result from a legitimate move or rename. Concluding manipulation without corroborating evidence such as tool artifacts or other anomalies would be premature and could mislead the investigation.

  • ✗

    The file was accessed by an antivirus scanner, which updated the $FILE_NAME access time and left $STANDARD_INFORMATION modification time unchanged.

    Why it's wrong here

    Antivirus scanning generally updates the access time, not the modification time, and does not update $FILE_NAME modification time. The observed difference is in modification and creation times, so an antivirus scan does not explain the pattern seen here.

  • ✗

    The file was created by the operating system during installation, and the newer $FILE_NAME times reflect the last time it was backed up.

    Why it's wrong here

    Backup operations do not normally update $FILE_NAME timestamps. The pattern of newer $FILE_NAME times relative to $STANDARD_INFORMATION is more consistent with a rename or move operation, not a backup, so this explanation does not fit the observed evidence.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.