Courseiva

CCNA Introduction To File System Timeline Forensics Questions

31 questions · Introduction To File System Timeline Forensics topic · All types, answers revealed

1
Multi-Selecthard

An investigator is analyzing a Windows 10 system and needs to correlate file system timestamps with other artifacts to build a comprehensive timeline. Which two of the following Windows artifacts can provide additional temporal context when combined with NTFS timestamps? (Choose two.)

Select 2 answers
A.Prefetch files
B.$MFT
C.$LogFile
D.Windows Event Logs
E.Registry hive files
AnswersA, D

Prefetch files (.pf) store information about applications executed on the system, including last run times and loaded files. They can be used to determine when an executable was run, which can be correlated with file creation or modification times. This helps establish cause and effect, such as an application creating or modifying files after execution. Prefetch is a key artifact for timeline enrichment.

Why this answer

Windows Event Logs and Prefetch files provide independent temporal data that can be correlated with NTFS timestamps. Event logs record system and user activities, while prefetch shows application execution. Together, they enrich a timeline by providing context for file system changes, helping analysts understand the sequence of events.

Exam trap

The trap here is selecting file system internal structures like $MFT or $LogFile, which are already part of the NTFS metadata, instead of external artifacts that provide additional context.

2
MCQeasy

Which of the following describes the 'MAC' in MACB times during timeline analysis?

A.Memory, Application, Cache, and Buffer.
B.Modification, Access, Change, and Birth.
C.Main, Auxiliary, Configuration, and Backup.
D.Master, Allocation, Cluster, and Bit-map.
AnswerB

Modification tracks content changes, Access tracks reading, Change tracks metadata updates, and Birth tracks file creation. These four points are essential for building a comprehensive view of file activity. By analyzing these, an investigator can determine if an attacker simply viewed a file or if they modified its contents.

Why this answer

MACB refers to the four primary timestamps: Modification, Access, Change, and Birth (Creation). These are the fundamental metadata points recorded by file systems. Understanding these timestamps is the core of timeline forensics, as they allow analysts to reconstruct the sequence of events.

Each timestamp provides a different perspective on how a file was interacted with, enabling the investigator to distinguish between reading, editing, and creating files on the disk.

Exam trap

Candidates occasionally confuse 'Change' with 'Creation,' thinking 'C' stands for creation. In NTFS, 'C' stands for MFT entry modification (Change), while 'Birth' represents the file creation time.

3
MCQeasy

A forensic analyst is building a timeline from an NTFS volume and wants to include the time when a file's metadata was last changed, such as permission modifications. Which timestamp should the analyst focus on to capture this event?

A.Accessed time (atime)
B.Entry modified time (ctime)
C.Modified time (mtime)
D.Creation time (crtime)
AnswerB

The entry modified time (ctime) in NTFS, also known as the MFT change time, is updated whenever the file's metadata or MFT record changes, including permission modifications, ownership changes, or attribute updates. It does not change when only file content is modified (that updates mtime). Thus, ctime is the correct timestamp to capture metadata changes like permission alterations.

Why this answer

In NTFS, the entry modified time (ctime) is updated whenever the file's MFT record is changed, which includes modifications to security descriptors, ownership, and other metadata. This makes it the correct timestamp for detecting permission changes. The modified time (mtime) only reflects data writes, the accessed time (atime) reflects reads, and the creation time (crtime) is fixed at file creation.

Thus, ctime is the key timestamp for metadata alterations such as permission modifications.

Exam trap

The trap here is confusing the entry modified time (ctime) with the creation time (crtime) or assuming that mtime captures all changes, when in fact ctime specifically records metadata changes like permissions.

4
MCQeasy

An analyst acquires a forensic image of a Windows 10 NTFS volume using a write blocker and now needs to build a file system timeline. The analyst wants to include the $STANDARD_INFORMATION timestamps but also wants to detect timestomping by comparing them with the $FILE_NAME timestamps. Which tool should the analyst use to extract both timestamp sets from the MFT and generate a bodyfile for timeline creation?

A.ntfs-3g
B.log2timeline.pl
C.MFTECmd
D.fls from The Sleuth Kit
AnswerC

MFTECmd parses the $MFT and outputs both $STANDARD_INFORMATION and $FILE_NAME timestamps in a CSV or bodyfile-compatible format. This allows the analyst to compare the two timestamp sets and detect timestomping, which is exactly what the scenario requires.

Why this answer

MFTECmd is specifically designed to parse the $MFT and output both $STANDARD_INFORMATION and $FILE_NAME timestamps, enabling direct comparison for timestomping detection. The other tools either do not extract both timestamp sets or are not intended for this purpose.

Exam trap

The trap here is assuming that any tool that can parse the MFT will automatically output both $STANDARD_INFORMATION and $FILE_NAME timestamps, when many only report the $STANDARD_INFORMATION set by default.

5
MCQmedium

An analyst is examining an NTFS volume and notices that a file's MFT entry shows a modification time earlier than its creation time. What is the most likely cause for this anomaly?

A.The file system is corrupted and requires an immediate CHKDSK operation.
B.The operating system experienced a clock drift during the file write process.
C.The file was moved from another volume or manipulated using timestomping techniques.
D.The master file table is using short filename (8.3) format which ignores creation time.
AnswerC

Moving a file across volumes creates a new entry with an updated creation time, while copying or direct metadata manipulation can force the modification time to an older value. Recognizing this behavior is essential because attackers often use tools to modify these attributes, attempting to blend malicious files into existing directory structures.

Why this answer

This anomaly is frequently caused by the 'timestomping' technique or a file move operation where the original metadata is preserved. By understanding file system internals, an analyst recognizes that MFT entry times are susceptible to manipulation via user-mode tools or low-level API calls. Detecting these inconsistencies is critical for identifying anti-forensics activity or specific file system behaviors that could lead to misinterpretation of the true timeline of events.

Exam trap

Candidates tend to immediately suspect only malware timestomping, forgetting that standard administrative actions like moving a file across volumes can also alter MFT timestamps.

6
MCQhard

An investigator is analyzing an NTFS volume from a Windows Server 2016 system that was recently compromised. The attacker used a tool to modify file timestamps to evade detection. The investigator notices that the $STANDARD_INFORMATION timestamps for a suspicious executable are all set to 2018-01-01, while the $FILE_NAME timestamps remain at 2021-06-15. The $MFT entry number is 12345. What is the most accurate conclusion regarding the timestamp manipulation?

A.Both sets of timestamps were modified, and the investigator cannot determine which one is original without additional artifacts.
B.The $FILE_NAME timestamps were modified by the attacker, and the $STANDARD_INFORMATION timestamps are the original ones.
C.The timestamps are consistent with normal system behavior, and no manipulation occurred.
D.The attacker used a tool that only modifies $STANDARD_INFORMATION timestamps, and the $FILE_NAME timestamps are likely original and reliable.
AnswerD

This is correct because many timestamp manipulation tools, such as timestomp, target only the $STANDARD_INFORMATION attribute by default. The $FILE_NAME attribute timestamps are stored in the directory entry and are not always updated by such tools unless they specifically target them. Therefore, the discrepancy between the two sets of timestamps strongly suggests that the $STANDARD_INFORMATION values were altered, while the $FILE_NAME values may still reflect the original file creation or modification times. The investigator should prioritize the $FILE_NAME timestamps as more reliable in this scenario.

Why this answer

The correct answer is the option stating that the attacker modified only $STANDARD_INFORMATION timestamps. Common timestomping tools like timestomp or SetMace often alter the $STANDARD_INFORMATION attribute without updating the $FILE_NAME attribute. This creates a discrepancy where $STANDARD_INFORMATION shows an earlier, uniform date while $FILE_NAME retains the original timestamp.

Investigators should compare both sets of timestamps and treat the $FILE_NAME values as more reliable when manipulation is suspected, as they are harder to modify without specialized tools.

Exam trap

The trap here is assuming that any timestamp manipulation affects both $STANDARD_INFORMATION and $FILE_NAME equally, when in fact many tools only modify the $STANDARD_INFORMATION attribute.

7
MCQmedium

When performing timeline analysis on a Linux system, which file is the most critical to examine to reconstruct user login and logout history?

A./var/log/syslog
B./var/run/utmp
C./var/log/wtmp
D./etc/passwd
AnswerC

The wtmp file is a binary log that records every login and logout event on the system. It is specifically designed for long-term audit purposes, making it the primary source for establishing a timeline of user access. Its binary nature ensures that it is not easily modified by standard users.

Why this answer

The wtmp file is the standard repository for historical login and logout data on Linux systems. By tracking session durations and connection origins, investigators can establish a user's presence during the time of an incident. This file is essential for building a reliable user-activity timeline, which provides the context needed to link specific file system changes to a particular user account or remote connection.

Exam trap

Test-takers frequently confuse authentication logs like auth.log with wtmp, missing that wtmp specifically serves as the binary repository for historical session durations and logins.

8
MCQeasy

A forensic analyst is examining a Linux ext4 file system and wants to determine when a file's metadata (such as permissions or ownership) was last changed. Which timestamp should they examine?

A.ctime
B.atime
C.btime
D.mtime
AnswerA

ctime (change time) is updated whenever the file's metadata changes, including permissions, ownership, or when the file is renamed. It is not the creation time. In this scenario, the analyst needs the time of metadata change, so ctime is the correct timestamp. It is stored in the inode and is crucial for tracking administrative changes.

Why this answer

On Linux ext4, ctime is updated when file metadata changes, such as permissions or ownership. mtime reflects content changes, atime reflects access, and btime is creation time. Therefore, ctime is the correct timestamp to determine when metadata was last altered.

Exam trap

The trap here is confusing ctime with creation time; ctime stands for change time, not creation time, and is updated on metadata changes.

9
MCQmedium

An investigator notices that a file's 'Birth' time is later than its 'Modification' time. What is the most likely forensic explanation for this phenomenon?

A.The file system is corrupted
B.The file was copied from an external source
C.The system clock was updated via NTP
D.The file is a system-level shadow copy
AnswerB

When copying a file, the OS creates a new entry on the destination volume, setting a new birth time. However, many copy utilities and APIs preserve the original modification timestamp from the source file. This results in the metadata anomaly where the file appears to be 'modified' before it was 'born'.

Why this answer

This scenario, often called 'time-traveling' files, typically occurs when a file is copied from another location. The copy process assigns a new 'Birth' time (the time of the copy), but the 'Modification' time is often preserved from the original source file. Recognizing this artifact is crucial for distinguishing between files created locally and those that were moved or copied by an attacker into the environment during an incident.

Exam trap

Candidates often assume the file is corrupted or the system clock is broken, failing to recognize the 'time-traveling' artifact common when files are copied from external sources.

10
MCQmedium

During a forensic investigation of a Windows 10 workstation, an analyst reviews the NTFS Master File Table (MFT) and notices that the $STANDARD_INFORMATION timestamps for a suspicious file are all dated 2023-08-15, but the $FILE_NAME timestamps are dated 2024-01-20. The file is located in C:\Users\Public\Downloads. Which of the following best explains this discrepancy?

A.The file system journal ($LogFile) recorded a system time change, causing the $STANDARD_INFORMATION timestamps to be adjusted while the $FILE_NAME timestamps remained unchanged.
B.The file was likely timestomped, as the $STANDARD_INFORMATION timestamps can be modified by user-mode tools while $FILE_NAME timestamps are harder to alter.
C.The file was copied from another NTFS volume, causing the $STANDARD_INFORMATION timestamps to reflect the original creation time while the $FILE_NAME timestamps reflect the copy time.
D.The file was restored from a backup, and the backup software restored the $STANDARD_INFORMATION timestamps but not the $FILE_NAME timestamps.
AnswerB

This is correct because timestomping tools typically modify the $STANDARD_INFORMATION attributes, which are easily accessible, while the $FILE_NAME timestamps in the MFT are less commonly altered. The discrepancy between the two sets of timestamps is a classic indicator of timestomping, especially when the $STANDARD_INFORMATION times are earlier than the $FILE_NAME times.

Why this answer

The correct answer is the option describing timestomping. In NTFS, $STANDARD_INFORMATION timestamps are easily modified by user-mode APIs, while $FILE_NAME timestamps are stored in the MFT and are more difficult to change. A large discrepancy where $STANDARD_INFORMATION times are earlier than $FILE_NAME times is a strong indicator of timestomping, often used by attackers to hide malicious files.

Exam trap

The trap here is assuming that any timestamp discrepancy is due to benign system activity, when in fact it often indicates deliberate timestomping.

11
MCQmedium

Why might an analyst prefer using 'Super-Timeline' creation tools, such as log2timeline, over manual collection of file system timestamps?

A.They automatically decrypt all files for easier analysis.
B.They provide a comprehensive view by integrating metadata from multiple sources.
C.They eliminate the need to preserve original forensic images.
D.They ensure all files are permanently deleted from the disk.
AnswerB

By combining registry, log, and file system artifacts, these tools provide a complete narrative. This integration allows the analyst to see the causal relationship between events, such as a process execution event in a log file followed by a file modification in the NTFS MFT, which is crucial for reconstruction.

Why this answer

Super-timelines aggregate data from diverse sources including file systems, event logs, registry hives, and application-specific artifacts into a single chronological view. Manual timestamp collection is limited to file system metadata, which often fails to capture the 'why' behind an event. By aggregating disparate data, analysts can correlate file changes with system events, providing a much richer, holistic context that is necessary to solve complex, multi-stage security incidents.

Exam trap

Candidates mistakenly believe that manual timestamp collection provides the same contextual depth as super-timelines, missing the crucial correlation with registry and event logs.

12
MCQmedium

A forensic analyst is creating a timeline from a Windows 10 workstation using fls and mactime from The Sleuth Kit. The analyst notices that the bodyfile contains entries with timestamps that appear to be off by several hours compared to the wall-clock time the incident was reported. The system is known to be set to UTC in the BIOS. Which action best ensures the timeline is correctly aligned for reporting?

A.Apply the Windows time zone setting from the registry to convert the timestamps to local time before analysis.
B.Discard the bodyfile and regenerate it using a tool that automatically converts timestamps to the analyst's local time zone.
C.Adjust each timestamp by the offset observed in the bodyfile until the timeline matches the incident report time.
D.Verify the time zone configuration and document whether timestamps are stored in UTC, then normalize all timeline entries to UTC for comparison.
AnswerD

NTFS stores timestamps in UTC, so normalizing the timeline to UTC removes ambiguity and ensures consistency across sources. Documenting the system's time zone configuration captures the context needed to interpret any user-facing times and supports a defensible report.

Why this answer

NTFS timestamps are recorded in UTC, so a timeline built from them should be normalized to UTC to avoid ambiguity and to allow correlation with other UTC-based sources such as event logs. Documenting the system's time zone configuration provides context for user-facing times but does not change the underlying UTC values. Arbitrary adjustment of timestamps undermines the integrity of the timeline.

Exam trap

The trap here is assuming that timestamps must be converted to local time to be useful, when UTC normalization is the defensible choice.

13
MCQhard

During a forensic investigation of a Windows 10 system, an analyst observes that a file's $STANDARD_INFORMATION creation timestamp is 2020-01-01 10:00:00, while its $FILE_NAME creation timestamp is 2020-01-01 10:00:05. The system time zone is UTC-5. The analyst also notes that the file's $STANDARD_INFORMATION modification timestamp is 2020-01-01 10:00:00. What is the most likely explanation for the 5-second difference between the creation timestamps?

A.The file was timestomped, and the attacker set the $STANDARD_INFORMATION creation time to match the modification time.
B.The 5-second difference indicates that the file was copied from another volume, and the $FILE_NAME creation time was updated to the copy time.
C.The 5-second difference is due to the file system tunneling feature, which preserves the original creation time from a deleted file with the same name.
D.The 5-second difference is normal because $STANDARD_INFORMATION and $FILE_NAME timestamps are updated at different times during file creation.
AnswerD

During file creation, the $STANDARD_INFORMATION timestamps are set first, and the $FILE_NAME timestamps are set slightly later. A small difference of a few seconds is common and not indicative of tampering. This is the most likely explanation for the observed 5-second gap.

Why this answer

A small difference of a few seconds between $STANDARD_INFORMATION and $FILE_NAME creation timestamps is normal and occurs because the two sets of timestamps are written at slightly different times during file creation. It is not necessarily an indicator of timestomping or other manipulation.

Exam trap

The trap here is assuming that any discrepancy between $STANDARD_INFORMATION and $FILE_NAME timestamps indicates malicious activity, when in fact minor differences are expected due to normal system behavior.

14
MCQmedium

During a forensic examination of an NTFS volume, an analyst notices that a file's $STANDARD_INFORMATION timestamps show a modification time of 2023-04-01 10:00:00, but the $FILE_NAME timestamps show a modification time of 2023-03-15 14:30:00. The file is not a system file and has not been renamed. What is the most likely explanation for this discrepancy?

A.The file was copied from another volume, preserving the $FILE_NAME timestamps but updating the $STANDARD_INFORMATION timestamps.
B.The file's $STANDARD_INFORMATION timestamps were modified by a timestomping tool, while the $FILE_NAME timestamps remained unchanged.
C.The file was moved within the same volume, which updates $STANDARD_INFORMATION but not $FILE_NAME timestamps.
D.The file system is corrupted, causing inconsistent timestamps between attributes.
AnswerB

Timestomping tools often target $STANDARD_INFORMATION timestamps because they are easily accessible via user-mode APIs. They may not update $FILE_NAME timestamps, especially if the file was not renamed. This creates a discrepancy where $STANDARD_INFORMATION shows a later modification time than $FILE_NAME. In this scenario, the file was not renamed, so $FILE_NAME timestamps should reflect the original modification time, making timestomping the most likely explanation.

Why this answer

Timestomping tools often alter $STANDARD_INFORMATION timestamps without updating $FILE_NAME timestamps, especially when the file is not renamed. This creates a discrepancy where $STANDARD_INFORMATION shows a later modification time than $FILE_NAME. Since the file was not renamed, the $FILE_NAME timestamps likely reflect the original modification time, indicating tampering.

Exam trap

The trap here is assuming that any timestamp discrepancy indicates file system corruption, when in fact timestomping is a common anti-forensic technique that targets specific attributes.

15
MCQeasy

An investigator is preparing to analyze a Windows 10 workstation's NTFS volume using a forensic tool that reads the master file table (MFT) directly. The goal is to build a timeline that includes timestamps for files that were deleted before the acquisition. Which artifact should the investigator primarily rely on to recover timestamps for deleted files?

A.The $LogFile transaction log
B.The $MFT file and its unallocated MFT entry records
C.The $UsnJrnl:$J change journal
D.The $Bitmap allocation file
AnswerB

Deleted file metadata often remains in unallocated MFT entries until overwritten. Parsing the $MFT, including unallocated entries, allows recovery of $STANDARD_INFORMATION and $FILE_NAME timestamps for deleted files, enabling their inclusion in the timeline even though the file content is gone.

Why this answer

Unallocated MFT entries preserve the $STANDARD_INFORMATION and $FILE_NAME attributes of deleted files until those entries are reused. By parsing the $MFT, including slack and unallocated records, an analyst can recover the four MACB timestamps for files that no longer exist in the active file system, which is essential for a complete forensic timeline.

Exam trap

The trap here is assuming that deleted files leave no timestamp evidence once their MFT entry is marked as unallocated, when in fact the record content often persists until reuse.

16
Multi-Selectmedium

A forensic analyst is building a file system timeline from an NTFS volume and wants to ensure it includes reliable evidence of file creation and deletion events. Which two artifacts should the analyst prioritize to capture these events? (Choose two.)

Select 2 answers
A.Volume Shadow Copy snapshots
B.$MFT entries, including unallocated records
C.$UsnJrnl:$J change journal
D.$LogFile transaction log
E.$Bitmap allocation file
AnswersB, C

$MFT entries contain the $STANDARD_INFORMATION and $FILE_NAME attributes with creation, modification, access, and entry modification timestamps. Unallocated entries can preserve timestamps for deleted files until reused, making the $MFT essential for both creation and deletion timeline events.

Why this answer

The $MFT, including unallocated entries, provides timestamps for files that existed or were deleted. The $UsnJrnl:$J logs file system changes with timestamps, capturing creation and deletion events. Together, they offer a robust foundation for a file system timeline, allowing analysts to correlate timestamps and change records.

Exam trap

The trap here is overlooking unallocated $MFT entries, which can still contain timestamps for deleted files, or assuming the $LogFile is a primary timeline source.

17
MCQhard

During a timeline review of an NTFS volume, an analyst observes that a file's $STANDARD_INFORMATION modification time is several days earlier than its $FILE_NAME modification time, and the $STANDARD_INFORMATION creation time is also earlier than the $FILE_NAME creation time. The file is a suspected malware dropper. Which conclusion is best supported by this pattern?

A.The file was likely moved or renamed after its last content modification, causing the $FILE_NAME timestamps to update while $STANDARD_INFORMATION times remained older.
B.The file's timestamps were definitely manipulated with a timestomping tool that altered $STANDARD_INFORMATION.
C.The file was accessed by an antivirus scanner, which updated the $FILE_NAME access time and left $STANDARD_INFORMATION modification time unchanged.
D.The file was created by the operating system during installation, and the newer $FILE_NAME times reflect the last time it was backed up.
AnswerA

A move or rename within the same volume updates the $FILE_NAME timestamps but does not necessarily update $STANDARD_INFORMATION. The observed gap where $FILE_NAME times are newer than $STANDARD_INFORMATION times is consistent with such an operation and provides a plausible timeline sequence.

Why this answer

When a file is moved or renamed within an NTFS volume, the $FILE_NAME attribute timestamps are updated to the time of the operation, while $STANDARD_INFORMATION timestamps may remain unchanged. This produces a pattern where $FILE_NAME times are newer than $STANDARD_INFORMATION times. While timestomping can also create discrepancies, it typically makes $STANDARD_INFORMATION appear older, and without additional indicators the move or rename explanation is better supported by the specific pattern observed.

Exam trap

The trap here is jumping to timestomping whenever the two attribute timestamp sets disagree, without considering legitimate rename or move operations.

18
MCQmedium

What is the primary function of the $LogFile in NTFS when reconstructing a timeline?

A.To store the actual file content data for quick retrieval
B.To track all user-level file access and modification events
C.To record metadata transactions for file system integrity
D.To store backup copies of the Master File Table
AnswerC

The $LogFile is an essential component for NTFS transaction integrity. For a forensic investigator, it provides a chronologically ordered record of metadata changes. This allows for the reconstruction of recent events, enabling the identification of file system activity even if the standard MFT record has been updated or overwritten.

Why this answer

The $LogFile is a circular buffer that records metadata transactions for the file system. It is invaluable for forensic analysts because it captures recent changes to the file system, including those that might not yet be committed to the MFT. By parsing the $LogFile, investigators can recover evidence of file creations, deletions, or renames that occurred shortly before an incident, providing a granular view of recent activity that might otherwise be lost.

Exam trap

Candidates often mistake the $LogFile for a user activity log, failing to realize it is a low-level file system integrity mechanism that tracks metadata transactions, not user actions.

19
MCQmedium

Which of these is the primary limitation of using a file system 'Birth' time as a definitive event marker?

A.It is not recorded in the MFT for small files
B.It is reset during file move or copy operations
C.It is only available on newer versions of Windows
D.It is protected from being read by forensic tools
AnswerB

Moving or copying a file creates a new entry in the file system, which results in a new birth timestamp. This destroys the original creation evidence, making the birth time useless for determining when the file first arrived on the system if it has been moved or copied by the attacker.

Why this answer

The 'Birth' time is highly vulnerable to being reset or changed during common file operations, such as moving or copying files to a new location or restoring from a backup. Because it does not represent the original, immutable creation of the file in the environment, it cannot be reliably used as a 'ground truth' for when an attacker first introduced the file to the system. Investigators must corroborate this with other evidence.

Exam trap

Candidates incorrectly assume 'Birth' time is an immutable record of when a file was first created, forgetting that copy operations frequently generate a new 'Birth' timestamp for the destination file.

20
MCQmedium

An investigator is analyzing a Linux ext4 file system and needs to determine when a file's content was last modified. The file's inode contains ctime, mtime, and atime fields. Which timestamp should the investigator use to answer this specific question?

A.ctime
B.crtime
C.mtime
D.atime
AnswerC

mtime records the last time the file's content was modified. In ext4, any write to the file data updates mtime, making it the correct timestamp for determining when the content last changed. This directly answers the investigator's question about content modification time, assuming no timestamp manipulation has occurred.

Why this answer

In ext4, the mtime (modification time) field in the inode is updated whenever the file's content changes. It is the appropriate timestamp for determining when the file's data was last written. Other timestamps like ctime and atime serve different purposes and do not reflect content modification.

Exam trap

The trap here is confusing ctime with content modification time, when ctime actually tracks inode metadata changes.

21
MCQeasy

An analyst is creating a timeline from a forensic image of a Windows 7 system using The Sleuth Kit's fls and mactime tools. The analyst notices that the timeline includes entries for files that no longer exist on the volume. Which NTFS artifact is most likely responsible for these entries, and how should the analyst interpret them?

A.The $LogFile contains records of file system transactions, and it retains entries for files that were deleted, which the tool interprets as current files.
B.The $UsnJrnl records all changes to files, including deletions, and it retains the file names and timestamps for deleted files indefinitely.
C.The $MFT contains entries for deleted files that have not been overwritten, and these entries represent files that once existed and may still be recoverable.
D.The $Bitmap tracks cluster allocation, and it includes entries for files that were deleted but whose clusters have not been reallocated.
AnswerC

This is correct because the $MFT retains entries for deleted files until they are overwritten. When a file is deleted, its MFT record is marked as unallocated, but the record content, including timestamps and file name, often remains intact. The Sleuth Kit's fls tool can parse these unallocated entries and include them in the bodyfile, resulting in timeline entries for files that no longer exist. These entries are valuable because they indicate past file presence and can be used to reconstruct historical activity, and the data may still be recoverable if the clusters have not been reused.

Why this answer

The correct answer is the option describing the $MFT. NTFS keeps MFT records for deleted files in an unallocated state until they are reused. The Sleuth Kit's fls tool reads these records and includes them in the bodyfile, causing deleted files to appear in the timeline.

Investigators should interpret such entries as evidence of past file existence and potential recoverable data. The $MFT is a primary source for file system timeline reconstruction, especially for files that have been deleted but not overwritten.

Exam trap

The trap here is assuming that deleted files cannot appear in a timeline generated by fls, when in fact unallocated MFT entries are parsed and can produce such entries.

22
MCQmedium

During a forensic investigation of an NTFS volume, an analyst notices that the $MFT record for a suspicious executable shows a modified time earlier than its creation time. What does this specific anomaly typically indicate?

A.The file system metadata was actively corrupted by malware to hinder timeline analysis.
B.The file was copied from another location, preserving the original modified timestamp while generating a new creation timestamp.
C.The operating system experienced a severe clock synchronization failure during the write operation.
D.An automated defragmentation utility reorganized the cluster chain and inadvertently swapped the metadata values.
AnswerB

Copying a file to a new NTFS destination assigns a fresh creation timestamp representing the exact moment of creation on the target volume. However, the modified timestamp is often preserved from the source file, creating an apparent chronological inversion that immediately flags the file as a copy.

Why this answer

An $MFT record reflecting a modified time earlier than the creation time frequently occurs when a file is copied rather than moved. The copy operation assigns a new creation timestamp to the destination file while preserving the original modified timestamp from the source file. Recognizing this artifact helps forensic analysts trace the origin of stolen payloads across network shares or external drives.

Exam trap

Candidates often assume this is a sign of timestomping or system clock manipulation. They overlook the standard behavior of file systems when copying files across volumes.

23
Multi-Selecthard

A forensic analyst is examining an NTFS volume and wants to identify potential timestomping. Which TWO artifacts should the analyst compare to detect inconsistencies in file timestamps? (Choose two.)

Select 2 answers
A.$FILE_NAME timestamps
B.Volume Boot Record (VBR) timestamps
C.$Bitmap timestamps
D.Master File Table (MFT) record header timestamps
E.$STANDARD_INFORMATION timestamps
AnswersA, E

$FILE_NAME timestamps are updated by the file system during filename operations and are not directly modifiable by user-mode APIs. They often retain original values even when $STANDARD_INFORMATION is altered. Comparing these with $STANDARD_INFORMATION can expose timestomping. In this scenario, they are a key artifact for detecting inconsistencies.

Why this answer

Timestomping often modifies $STANDARD_INFORMATION timestamps while leaving $FILE_NAME timestamps unchanged. Comparing these two sets can reveal inconsistencies that indicate manipulation. Other artifacts like VBR, $Bitmap, or MFT record headers do not contain comparable per-file timestamps, so they are not useful for this specific detection.

Exam trap

The trap here is assuming that all NTFS metadata contains file timestamps, when only specific attributes like $STANDARD_INFORMATION and $FILE_NAME store them.

24
MCQmedium

An investigator is building a file system timeline for an NTFS volume from a Windows 10 workstation. The user claims a file was copied to an external drive at 14:00, but the file's NTFS Standard Information Attribute shows only a modification timestamp of 13:45. Which NTFS artifact should the investigator examine to determine when the filename was actually created or renamed on the volume?

A.$FILE_NAME creation time
B.$LogFile transaction records
C.Volume Shadow Copy creation time
D.$STANDARD_INFORMATION creation time
AnswerA

The $FILE_NAME attribute in the MFT records a timestamp that is updated when a filename is created or changed on the volume. For a copied or renamed file, this timestamp can reflect the time the filename entry was established, which may differ from the $STANDARD_INFORMATION creation time. In this scenario, it is the appropriate artifact to check for the filename creation event around 14:00.

Why this answer

The $FILE_NAME attribute creation timestamp is updated when a filename is created or changed on an NTFS volume, making it a key artifact for detecting copy or rename activity. Unlike $STANDARD_INFORMATION, it is less commonly manipulated by user-mode APIs. In this case, it can reveal whether the filename appeared around 14:00, supporting or contradicting the user's statement.

Exam trap

The trap here is assuming the $STANDARD_INFORMATION creation time always reflects the original file creation, when it can be altered and may not capture filename changes.

25
MCQeasy

An analyst is building a file system timeline from an NTFS volume and is deciding which timestamps to extract from the $STANDARD_INFORMATION attribute. A colleague suggests that the four timestamps in $STANDARD_INFORMATION are the only relevant times. Which statement correctly describes the relationship between $STANDARD_INFORMATION and $FILE_NAME timestamps?

A.$STANDARD_INFORMATION timestamps are always more reliable than $FILE_NAME timestamps and should be used exclusively.
B.$FILE_NAME timestamps are only populated when a file is created and never change afterward.
C.$FILE_NAME timestamps are duplicates of $STANDARD_INFORMATION and can be ignored.
D.$STANDARD_INFORMATION and $FILE_NAME each contain four timestamps, and comparing them can reveal timestamp manipulation or file moves.
AnswerD

Both attributes hold creation, modification, MFT change, and access times. Because they are updated by different code paths, discrepancies between them can indicate timestomping or a file move or rename, making both sets valuable for a defensible timeline.

Why this answer

NTFS stores timestamps in both the $STANDARD_INFORMATION and $FILE_NAME attributes of an MFT record. The two sets are maintained by different mechanisms and can disagree, which is itself valuable evidence. An analyst should extract both and compare them rather than relying on a single source, because the discrepancies often indicate moves, renames, or deliberate timestamp alteration.

Exam trap

The trap here is treating one attribute's timestamps as authoritative and ignoring the other, which discards corroborating or contradictory evidence.

26
MCQmedium

An investigator is adding NTFS USN change journal records to a file system timeline on a Windows 10 workstation. The journal was captured live with fsutil usn readjournal and shows a record with Reason value 0x00000100 (DATA_OVERWRITE) for a user document. The investigator wants to determine whether the file content was actually altered at that moment. Which statement best describes what the USN record establishes?

A.The record only shows that the file was opened for read access, because DATA_OVERWRITE is logged when the data stream is read.
B.The record indicates only that the file's MFT metadata was updated, not that the file data stream changed.
C.The record confirms the file was deleted and then re-created with the same name at the recorded time.
D.The record proves the file's data stream was overwritten at the time of the USN entry and can anchor the timeline for content modification.
AnswerD

DATA_OVERWRITE (0x00000100) indicates that data in the file was overwritten at the recorded time. Because the USN journal is written when the change occurs, this record is a reliable anchor for content modification on the timeline, assuming the journal has not wrapped and overwritten older records.

Why this answer

USN journal records capture specific change reasons at the moment they occur, and DATA_OVERWRITE specifically denotes that file data was overwritten. When the journal is intact and not wrapped, this gives the investigator a strong anchor for content modification. Other flags correspond to metadata or lifecycle events, so the reason code must be read literally.

Exam trap

The trap here is assuming any USN record reflects a content change rather than reading the specific Reason flag.

27
MCQmedium

When creating a super-timeline using tools like log2timeline, why is it critical to filter the output data?

A.Filtering increases the precision of the file system's internal clock
B.Filtering removes redundant entries to prevent system crashes during analysis
C.Filtering isolates relevant events from the massive volume of benign system activity
D.Filtering is required to encrypt the timeline output for secure storage
AnswerC

Super-timelines aggregate thousands of events, most of which are benign OS background tasks. Effective filtering narrows the scope to relevant timeframes or specific file types, enabling the analyst to quickly identify meaningful patterns of attacker behavior that would otherwise be obscured by the sheer volume of normal operating activity.

Why this answer

Super-timelines ingest massive amounts of data from diverse sources, including system logs, web history, and file system metadata. Without filtering, the volume of 'noise' from routine system activity makes it nearly impossible to isolate the specific events relevant to an incident. Filtering allows the investigator to focus on anomalous patterns and specific time windows, drastically increasing the efficiency and accuracy of the forensic reconstruction process during a high-pressure investigation.

Exam trap

Test-takers often assume raw super-timelines are self-explanatory, underestimating the overwhelming volume of benign noise that obscures actual malicious indicators.

28
MCQeasy

Why should a forensic analyst avoid using the 'Last Accessed' time as the primary indicator for a file's usage?

A.It is only updated if the file is moved to a different folder
B.It is unreliable due to frequent updates by system services
C.It is the most easily forged timestamp in the MFT
D.It only exists on FAT32 file systems
AnswerB

Access times are updated by nearly any process that reads a file, including security software, search indexers, and background tasks. This makes it impossible to distinguish between a malicious user accessing a document and a background service performing a routine scan, rendering the timestamp unreliable for proving intentional user interaction.

Why this answer

The 'Last Accessed' timestamp is notoriously unreliable in forensic analysis because it is frequently updated by non-human system activity, such as antivirus scans or indexing services. Furthermore, many systems have the 'noatime' option enabled, which stops the OS from updating this field entirely. Because of this noise and potential for total absence, relying on this value for evidence of user activity is inherently dangerous and prone to producing false positives.

Exam trap

Candidates often assume that 'Last Accessed' timestamps reliably indicate when a user opened a file, overlooking frequent background system updates and the 'noatime' filesystem setting.

29
MCQeasy

In the context of forensic timeline analysis, what does the term 'Time Skew' refer to?

A.The difference between local time and UTC
B.The intentional modification of a file's timestamp
C.The discrepancy between the system clock and the actual time
D.The process of normalizing timestamps to a common format
AnswerC

Time skew represents the drift or offset of a system clock compared to an accurate reference time. It is a critical factor for forensic analysts to document; failing to account for it will result in an incorrect sequence of events when comparing the evidence against other system logs or external timestamps.

Why this answer

Time skew is the difference between the actual wall-clock time and the time reported by the system under investigation. Identifying and correcting for this skew is a fundamental prerequisite for timeline analysis. If the investigator ignores the skew, all events will be chronologically misaligned, making it impossible to correlate evidence across different machines or correlate logs with file system activity during the incident reconstruction phase.

Exam trap

Candidates often treat the system time as absolute truth, failing to account for the drift between the local machine clock and the actual UTC time during multi-system correlation.

30
MCQhard

An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?

A.The ext4 journal aggressively overwrites inode metadata before user-space tools can parse the raw blocks.
B.The operating system automatically randomizes inode timestamps every 24 hours to prevent precise profiling.
C.Mount options such as relatime or noatime suppress continuous updates to file access timestamps to improve performance.
D.The Sleuth Kit parser inherently misinterprets the 64-bit epoch time structures utilized by modern Linux kernels.
AnswerC

Performance tuning options like relatime update access times only if the previous access time is older than the modification time or if it has been over a day. This intentional kernel behavior hides casual file reads, undermining traditional timeline analysis techniques used in incident response.

Why this answer

The ext4 file system supports the noatime mount option, which disables the updating of access times whenever files are read. This optimization significantly reduces disk I/O overhead but blinds investigators to critical file access timelines, making it difficult to prove whether a specific binary was actually executed by a local user.

Exam trap

Students frequently rely blindly on file access timestamps without checking file system mount options, leading to false assumptions about user activity.

31
MCQeasy

A forensic analyst is using a tool to generate a file system timeline from an NTFS volume. The tool outputs timestamps with nanosecond precision, but the analyst knows that NTFS stores timestamps with 100-nanosecond resolution. What is the most likely reason for the discrepancy?

A.The tool is incorrectly interpreting the timestamp format, treating them as nanoseconds instead of 100-nanosecond intervals.
B.The tool is reading timestamps from a different file system that stores nanosecond precision.
C.The tool is converting the 100-nanosecond intervals to nanoseconds and displaying additional precision that does not exist.
D.The NTFS file system on this volume has been upgraded to support nanosecond timestamps.
AnswerC

NTFS stores timestamps as 64-bit values representing the number of 100-nanosecond intervals since January 1, 1601. When a tool converts these to nanoseconds, it multiplies by 100, which can result in values that appear to have nanosecond precision but are actually limited to 100-nanosecond granularity. The extra digits are an artifact of conversion, not additional precision.

Why this answer

NTFS timestamps are stored as 64-bit values in 100-nanosecond intervals. When a forensic tool displays them, it often converts to nanoseconds for readability, which can introduce apparent nanosecond precision. The underlying resolution remains 100 nanoseconds, so the extra digits are not meaningful for timeline granularity.

Exam trap

The trap here is believing that the displayed precision reflects the actual storage resolution, leading to overconfidence in sub-100-nanosecond event ordering.

Ready to test yourself?

Try a timed practice session using only Introduction To File System Timeline Forensics questions.