Courseiva

GCFA · topic practice

File System Timeline Artifact Analysis practice questions

This GCFA domain covers reconstructing activity from file system metadata across NTFS and ext4. Candidates use fls, mactime, and $MFT parsing to interpret MACB timestamps, $STANDARD_INFORMATION versus $FILE_NAME discrepancies, and anti-forensic timestamp manipulation. Questions present artifact combinations and require correct interpretation of what each timestamp change implies about user or system activity.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: File System Timeline Artifact Analysis

What the exam tests

What to know about File System Timeline Artifact Analysis

A candidate must interpret MACB timestamp combinations across NTFS and ext4 artifacts and explain what each change indicates. The most important thing is distinguishing legitimate system updates from anti-forensic manipulation by cross-checking $STANDARD_INFORMATION against $FILE_NAME timestamps and inode metadata.

Interpreting ext4 inode ctime, atime, and mtime changes via fls and mactime output

Comparing NTFS $STANDARD_INFORMATION MACB timestamps against $FILE_NAME timestamps for discrepancies

Using $MFT record 0 and $MFT metadata to anchor NTFS timeline construction

Recognizing anti-forensic techniques such as timestomping and secure deletion that alter file system timelines

Watch out for

Common File System Timeline Artifact Analysis exam traps

  • ▸Assuming a changed ctime always means content modification, when metadata-only changes like permissions or ownership also update ctime.
  • ▸Treating $STANDARD_INFORMATION timestamps as authoritative without checking $FILE_NAME, which timestomping tools often leave inconsistent.
  • ▸Overlooking $MFT record 0 or $MFTMirr when building timelines, missing metadata that establishes the volume's baseline.

Practice set

File System Timeline Artifact Analysis questions

20 questions · select your answer, then reveal the explanation

An analyst is investigating an NTFS volume and notices that a file's $STANDARD_INFORMATION attribute modified timestamp is significantly earlier than its $FILE_NAME attribute modified timestamp. What is the most likely cause of this discrepancy during a forensic examination?

An analyst is investigating a suspected malware execution. They notice the MFT entry for 'svchost.exe' shows a file creation time that is earlier than the MFT record modification time. Which artifact-based technique should the analyst employ to determine if a timestomp occurred?

Which TWO of the following artifacts provide the most reliable evidence for reconstructing file system access history during a timeline analysis?

Refer to the exhibit. Based on the provided MFT attributes, what is the most likely conclusion regarding this file?

Exhibit

MFT Entry: 12345
SI Created: 2023-01-01 10:00:00
SI Modified: 2023-01-01 10:05:00
FN Created: 2023-01-05 12:00:00
FN Modified: 2023-01-05 12:05:00

When conducting a timeline analysis, which artifact is considered the most reliable source for determining when a file was actually deleted from an NTFS volume?

An analyst discovers a file with a 'Last Accessed' time that is significantly earlier than its 'Creation' time. What is the most appropriate forensic interpretation of this observation?

Which THREE of the following artifacts are commonly utilized to corroborate file system activity in a timeline analysis?

During a deep dive into an NTFS volume, you encounter a file where the $SI creation time is later than the $SI modification time. What does this indicate?

Which artifact is most useful for identifying the 'User' account associated with the creation of a specific file on a Windows system?

When analyzing the $MFT, what is the significance of an entry having a sequence number of 1?

Which of the following describes the purpose of the 'Standard Information' (SI) attribute in an NTFS MFT record?

During an NTFS file system timeline analysis using Sleuth Kit tools, an analyst observes multiple entries where the $MFT record's link count dropped to zero, yet data runs remain allocated. Which TWO file system phenomena or actions could produce this specific timeline artifact pattern?

When constructing a filesystem timeline on a Linux EXT4 system, which artifact is the most reliable indicator of file metadata modification (mtime) versus status change time (ctime)?

Which TWO of the following actions typically result in a modification of the $Standard_Information attribute in an NTFS filesystem?

Based on the MFT exhibit, what conclusion can the forensic analyst draw about the file?

Exhibit

Refer to the exhibit.
[MFT Entry 1234]
$STANDARD_INFORMATION: Mod: 2023-05-01 10:00:00.000, Acc: 2023-05-01 10:00:00.000, Chg: 2023-05-01 10:00:00.000, Birth: 2023-05-01 10:00:00.000
$FILE_NAME: Mod: 2023-05-01 12:00:00.000, Acc: 2023-05-01 12:00:00.000, Chg: 2023-05-01 12:00:00.000, Birth: 2023-05-01 12:00:00.000

A forensic analyst is reviewing an NTFS $MFT extracted from a compromised server. For one suspicious executable, the $STANDARD_INFORMATION timestamps show creation and modification in 2019, but the $FILE_NAME timestamps show creation and modification in 2022. The system clock was verified as accurate throughout. Which conclusion is BEST supported by this discrepancy?

An analyst is reviewing an NTFS volume with the Sleuth Kit and notices that a file's $STANDARD_INFORMATION modified timestamp is 2023-04-01 09:12:00, while its $FILE_NAME modified timestamp is 2023-03-15 14:22:00. The analyst must determine which timestamp is more reliable for the actual file content modification. Which timestamp should be trusted, and why?

An analyst is reviewing an NTFS volume using TSK tools and runs `istat $MFT` on a file entry. The output shows that the $FILE_NAME attribute contains a Created timestamp of 2024-03-10 09:14:22, while the $STANDARD_INFORMATION attribute contains a Created timestamp of 2024-03-10 09:15:47. The file is a user document, and no timestomping tools were detected. What is the most likely reason for the 85-second discrepancy?

During a forensic examination of a Windows 10 NTFS volume, an analyst runs `fls -m C: -o 2048 -r /dev/sda1 > body.txt` and `mactime -b body.txt -d -z UTC > timeline.csv`. The analyst observes that a suspicious executable, `update.exe`, has an $STANDARD_INFORMATION (SI) modified timestamp of 2024-03-10 14:22:00 and a $FILE_NAME (FN) modified timestamp of 2024-03-10 14:25:30. Both timestamps are in UTC. What is the most likely explanation for the 3.5-minute discrepancy between the SI and FN timestamps?

An investigator is building a file system timeline from an NTFS volume and wants to corroborate when a specific document was last accessed by a user. The volume has USN journal enabled and the system has been running continuously for weeks. Which TWO of the following artifacts would BEST support establishing the last access event in the timeline? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused File System Timeline Artifact Analysis sessions

Start a File System Timeline Artifact Analysis only practice session

Every question in these sessions is drawn from the File System Timeline Artifact Analysis domain — nothing else.

Related practice questions

Related GCFA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCFA exam test about File System Timeline Artifact Analysis?
A candidate must interpret MACB timestamp combinations across NTFS and ext4 artifacts and explain what each change indicates. The most important thing is distinguishing legitimate system updates from anti-forensic manipulation by cross-checking $STANDARD_INFORMATION against $FILE_NAME timestamps and inode metadata.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just File System Timeline Artifact Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the File System Timeline Artifact Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCFA topics?
Use the topic links above to move to related areas, or go back to the GCFA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCFA exam covers. They are not copied from any real exam or dump site.