GCFA NTFS Artifact Analysis Practice Question
During an investigation, you recover a deleted file from an NTFS volume. The MFT entry for the file shows that the $DATA attribute is non-resident, and the data runs are still intact. However, the $BITMAP attribute of the MFT indicates that the MFT entry is marked as unallocated. What is the most accurate conclusion about the recoverability of the file's content?
⚠ Common exam trap
The trap here is equating an unallocated MFT entry with unrecoverable data, overlooking that cluster allocation status is the decisive factor for content recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file content is likely recoverable, but you must check the $Bitmap metadata file to confirm the clusters are not reallocated.
When an MFT entry is unallocated, the file's data runs may still be present, but the clusters they point to could have been reallocated. The $Bitmap metadata file tracks which clusters are in use. To determine recoverability, the analyst must check whether the clusters are marked as free in $Bitmap. If free, the content can likely be recovered; if allocated, the content may be overwritten.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The file content is likely recoverable, but you must check the $Bitmap metadata file to confirm the clusters are not reallocated.
Why this is correct
The $Bitmap file tracks cluster allocation. Even if the MFT entry is unallocated, the clusters may still be free. Checking $Bitmap confirms whether the data runs point to allocated clusters. If the clusters are free, recovery is likely; if allocated, the content may be partially or fully overwritten.
- ✗
The file content is unrecoverable because the MFT entry is unallocated, which means the data runs are invalid.
Why it's wrong here
An unallocated MFT entry does not automatically invalidate its data runs. The MFT entry may still contain the runlist, and the clusters may remain unallocated. Many forensic tools can recover files from unallocated MFT entries if the clusters are not overwritten. Declaring it unrecoverable without checking cluster status is premature.
- ✗
The file content can be fully recovered because the data runs are intact and point to clusters that have not been overwritten.
Why it's wrong here
While intact data runs suggest recoverability, the clusters may have been reallocated to other files, especially if the volume has been in use. The $BITMAP only indicates the MFT entry is unallocated, not the clusters. Without verifying cluster allocation status, full recovery is not guaranteed.
- ✗
The file content can be recovered only if the $LogFile contains a record of the file's deletion.
Why it's wrong here
The $LogFile records metadata transactions, not file content. It may help reconstruct the MFT entry, but recovery of content depends on cluster availability. The presence of a deletion record in $LogFile does not guarantee that clusters are intact. This option misstates the role of $LogFile in file recovery.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.