GCFA File System Timeline Artifact Analysis Practice Question
During an investigation of a Windows system, an analyst is reviewing a supertimeline and observes that a suspicious executable's $STANDARD_INFORMATION timestamps are all set to a date years before the operating system was installed, while its $FILE_NAME timestamps reflect the actual installation period. The analyst suspects timestomping. Which conclusion is most defensible based on NTFS timestamp behavior?
⚠ Common exam trap
The trap here is assuming the two NTFS timestamp sets always agree, when a selective backward shift in $STANDARD_INFORMATION is a classic timestomping indicator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The $STANDARD_INFORMATION timestamps were likely altered by a tool that manipulates file times, since they precede the OS installation while $FILE_NAME reflects the true period
NTFS stores two independent timestamp sets: $STANDARD_INFORMATION, which is writable through common APIs and is the usual target of timestomping tools, and $FILE_NAME, which is updated only on filename-related operations and is harder to alter. A large backward shift in $STANDARD_INFORMATION that predates the OS installation, paired with $FILE_NAME timestamps matching real activity, is strong evidence of deliberate timestamp manipulation rather than normal system behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file's $MFT record sequence number was incremented, which reset the $STANDARD_INFORMATION timestamps to the volume creation date
Why it's wrong here
An $MFT record sequence number increments when the record is reused for a new file, not when timestamps are altered. Reuse would affect the entire record, including $FILE_NAME, and would not selectively set $STANDARD_INFORMATION to a pre-OS date while leaving $FILE_NAME intact. This option misattributes the cause and does not explain the specific discrepancy observed.
- ✗
The $FILE_NAME timestamps are unreliable because NTFS updates them only when the file is renamed
Why it's wrong here
NTFS updates $FILE_NAME timestamps on operations that change the filename entry, such as creation, rename, and sometimes when the file is moved within the same volume. They are not updated on every write, unlike $STANDARD_INFORMATION. However, they are still valuable and, in this scenario, reflect the actual installation period. Declaring them unreliable misstates NTFS behavior and would discard corroborating evidence of timestomping.
- ✗
The discrepancy indicates the file was created by the operating system installer and later modified by a user
Why it's wrong here
Operating system installer files typically have $STANDARD_INFORMATION and $FILE_NAME timestamps that are consistent with the installation period, not years earlier than the OS install. A large backward discrepancy in $STANDARD_INFORMATION relative to $FILE_NAME is a known timestomping indicator, so attributing it to normal installer behavior misinterprets the evidence and ignores the anti-forensic pattern.
- ✓
The $STANDARD_INFORMATION timestamps were likely altered by a tool that manipulates file times, since they precede the OS installation while $FILE_NAME reflects the true period
Why this is correct
Timestomping tools commonly modify $STANDARD_INFORMATION timestamps because they are writable via user-mode APIs, while $FILE_NAME timestamps are harder to alter and often retain the true creation and modification periods. When $STANDARD_INFORMATION predates the OS installation and $FILE_NAME matches the actual activity window, the defensible conclusion is deliberate timestamp manipulation of $STANDARD_INFORMATION.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.