Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

During an investigation of a compromised Windows 10 workstation, a forensic analyst reviews the NTFS $MFT and observes that the Standard Information Attribute (SIA) timestamps for a suspicious executable in C:\Windows\Temp are all identical, while the File Name Attribute (FNA) timestamps show a different, earlier date. The executable has no corresponding Prefetch file. Which conclusion is most strongly supported by these artifacts?

⚠ Common exam trap

The trap here is assuming that identical SIA timestamps prove the file was executed, when they actually suggest timestamp manipulation and the lack of Prefetch means execution is unconfirmed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file was likely placed by a tool that manipulated $STANDARD_INFORMATION timestamps to hinder timeline analysis, and it may not have been executed on this system.

Identical $STANDARD_INFORMATION timestamps paired with differing $FILE_NAME timestamps indicate timestomping, because the SIA can be modified by user-mode APIs while the FNA is updated only by the kernel during file creation or rename. The absence of a Prefetch file means the analyst cannot confirm execution from these artifacts alone, and the file's location in C:\Windows\Temp further supports a malicious or suspicious origin rather than normal installation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file was created by a legitimate installer that preserved original timestamps, and the lack of Prefetch is due to a disabled SysMain service.

    Why it's wrong here

    Legitimate installers rarely produce identical SIA timestamps across all four values; they typically update $STANDARD_INFORMATION on write. A disabled SysMain service would also affect other executables, and the analyst has no evidence of that. This explanation does not account for the earlier FNA timestamps, which indicate the file name entry was created before the SIA values were modified, a pattern inconsistent with normal installation.

  • ✗

    The file is encrypted by EFS, which alters $STANDARD_INFORMATION timestamps and prevents Prefetch creation until the file is decrypted.

    Why it's wrong here

    EFS does not modify $STANDARD_INFORMATION timestamps to be identical; it adds encryption attributes and may update the $LOGGED_UTILITY_STREAM, but the four SIA timestamps remain distinct. EFS also does not prevent Prefetch creation for an executable. The scenario provides no evidence of encryption, such as an encrypted attribute or certificate, so this explanation is unsupported by the artifacts described.

  • ✗

    The file is a legitimate Windows component that was moved from another volume, causing the SIA and FNA timestamps to diverge and Prefetch to be absent.

    Why it's wrong here

    Moving a file within the same volume preserves the $STANDARD_INFORMATION timestamps but does not create identical SIA values across all four fields. A cross-volume move would create a new file with updated SIA timestamps, not identical ones. The absence of Prefetch is not explained by a move operation, and there is no evidence the file is a Windows component given its location in C:\Windows\Temp.

  • ✓

    The file was likely placed by a tool that manipulated $STANDARD_INFORMATION timestamps to hinder timeline analysis, and it may not have been executed on this system.

    Why this is correct

    Identical SIA timestamps combined with different FNA timestamps are a classic sign of timestomping, where an attacker sets $STANDARD_INFORMATION to a false date. The earlier FNA timestamps reflect when the file name was actually created. The absence of a Prefetch file further suggests the executable may not have run, or Prefetch was cleared, so the analyst cannot assume execution from these artifacts alone.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.