GCFA File System Timeline Artifact Analysis Practice Question
During a Windows 10 intrusion investigation, an analyst uses fls on a raw NTFS image and observes that for a suspicious executable, the $FILE_NAME creation timestamp is 2023-08-10 14:22:01, while the $STANDARD_INFORMATION creation timestamp is 2023-08-10 14:22:01 as well, but the $STANDARD_INFORMATION modified timestamp is 2023-08-10 14:22:01 and the $FILE_NAME modified timestamp is 2023-08-10 14:22:01. However, the $MFT record header's last modification time (the MFT entry itself) is 2023-08-10 14:25:33. What is the most likely explanation for the discrepancy between the MFT record modification time and the file's timestamps?
⚠ Common exam trap
The trap here is assuming that any MFT record header timestamp change necessarily corresponds to a change in the file's $STANDARD_INFORMATION or $FILE_NAME timestamps, when in fact the MFT record can be updated for structural changes that do not affect those attributes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file's attributes or MFT record structure were modified at 14:25:33, such as a change in the $DATA attribute or the addition of an alternate data stream, without altering the $STANDARD_INFORMATION or $FILE_NAME timestamps.
The MFT record header contains a timestamp that reflects when the MFT entry itself was last modified, which can occur independently of the file's $STANDARD_INFORMATION and $FILE_NAME timestamps. Operations such as adding an alternate data stream, resizing the $DATA attribute, or changing the file's name can update the MFT record header without altering the timestamps stored in the attributes. Thus, the discrepancy indicates a change to the MFT record structure, not a simple file access or copy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The system clock was changed at 14:25:33, causing the MFT record header to be updated while the file timestamps remained unchanged.
Why it's wrong here
A system clock change would not selectively update the MFT record header timestamp without affecting other timestamps. If the clock were changed, any subsequent file operations would likely update the $STANDARD_INFORMATION modified time as well. Moreover, the MFT record header timestamp is updated only when the record is written to, not merely because the clock changed. This explanation does not account for the specific update to the MFT record.
- ✓
The file's attributes or MFT record structure were modified at 14:25:33, such as a change in the $DATA attribute or the addition of an alternate data stream, without altering the $STANDARD_INFORMATION or $FILE_NAME timestamps.
Why this is correct
The MFT record header timestamp is updated when the MFT entry itself is modified, such as when a new attribute is added, an attribute is resized, or the record is moved. Operations like adding an alternate data stream or changing the file's size can update the MFT record header without changing the $STANDARD_INFORMATION or $FILE_NAME timestamps, because those timestamps are stored in the attributes themselves. This explains the discrepancy while all file timestamps remain identical.
- ✗
The file was accessed at 14:25:33, and the NTFS file system updates the MFT record header on every access.
Why it's wrong here
NTFS does not update the MFT record header on every file access. The MFT record header timestamp is updated only when the MFT entry itself is modified, not when the file data is read. File access typically updates the $STANDARD_INFORMATION access timestamp (if enabled), not the MFT record header. Therefore, an access at 14:25:33 would not explain the MFT record header modification.
- ✗
The file was copied into the directory at 14:22:01, and the MFT record was later updated at 14:25:33 due to a backup operation.
Why it's wrong here
A copy operation would typically update the $STANDARD_INFORMATION creation time to the copy time and the $FILE_NAME creation time to the original creation time, causing a discrepancy between those two, not just the MFT record header. A backup operation may touch the MFT record, but the file's timestamps would likely change as well if the backup modified attributes. The scenario shows all file timestamps identical, so a copy is not the best explanation.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.