Courseiva

GCFA · topic practice

Introduction to File System Timeline Forensics practice questions

This domain covers building and interpreting file system timelines for forensics, focusing on NTFS and ext4 metadata, MACB timestamp semantics, and tools like log2timeline, Plaso, and The Sleuth Kit. Questions test whether you can extract, filter, and reason about timestamps rather than merely generate a timeline.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Introduction to File System Timeline Forensics

What the exam tests

What to know about Introduction to File System Timeline Forensics

You must be able to build a MACB file system timeline and correctly interpret each timestamp's meaning and reliability. The most important thing is knowing which timestamps are trustworthy versus user-modifiable, and filtering super-timeline output before drawing conclusions.

Extracting MACB timestamps from NTFS $STANDARD_INFORMATION and $FILE_NAME attributes

Using log2timeline/Plaso to build super-timelines and filter output for relevance

Interpreting ext4 timestamps via The Sleuth Kit fls and istat output

Recognizing time skew, clock drift, and timezone effects in timeline data

Watch out for

Common Introduction to File System Timeline Forensics exam traps

  • ▸Assuming $STANDARD_INFORMATION timestamps are reliable; they are easily modified by user-mode tools and can be forged.
  • ▸Treating every access time as proof of user interaction, ignoring atime update policies and filesystem mount options.
  • ▸Forgetting to normalize timezones and clock skew, producing timelines with misordered or misleading events.

Practice set

Introduction to File System Timeline Forensics questions

20 questions · select your answer, then reveal the explanation

Which TWO file system artifacts or parameters are critical for an analyst to examine when evaluating the reliability of NTFS $STANDARD_INFORMATION and $FILE_NAME attribute timestamps during a timeline analysis? (Choose two)

An analyst is reviewing a timeline generated from a compromised Windows workstation and notices a high volume of file accesses to various user documents immediately preceded by the creation of a prefetch file for a known archive utility. What forensic deduction can be made from this timeline sequence?

Which TWO limitations or challenges should a forensic investigator keep in mind when relying on file system timelines to reconstruct user activity? (Choose two)

An analyst is investigating an unauthorized file modification on an NTFS volume. Which set of timestamps provides the most reliable indicator of actual file content changes rather than metadata updates?

Which TWO of the following accurately describe the limitations of using MACB (Modified, Accessed, Changed, Birth) timelines in forensic investigations?

Which artifact is most useful for verifying file access if the file system 'atime' is disabled?

Which THREE of the following are valid reasons to include system event logs in a file system timeline?

Which action most effectively minimizes the risk of altering file system metadata during live forensic data collection?

Which THREE of the following represent common challenges when performing timeline analysis on a system with multiple time zones?

Which TWO of the following actions typically result in the update of the $Standard_Information attribute in an NTFS file system?

Refer to the exhibit. An analyst generated a timeline using the Sleuth Kit. What is the primary purpose of creating the bodyfile in this workflow?

Exhibit

C:\> fls -r -m C:/ C: > bodyfile.txt
C:\> mactime -b bodyfile.txt 2023-01-01..2023-01-31 > timeline.csv

Which THREE of the following represent potential weaknesses when relying exclusively on system timestamps for forensic timelines?

Refer to the exhibit. An investigator observes a discrepancy between the $Standard_Information and $File_Name timestamps in an NTFS MFT record. What is the most likely explanation for this difference?

Exhibit

MFT Entry: 12345
$Standard_Information: 2023-05-01 10:00:00
$File_Name: 2023-05-01 12:00:00

An investigator is analyzing a compromised Linux server and needs to build a timeline of file system activity. The server uses ext4. The investigator runs the command 'debugfs -R "stat /etc/passwd" /dev/sda1' and observes the following timestamps: ctime: 2024-02-10 08:15:32, atime: 2024-02-11 09:20:45, mtime: 2024-02-10 08:15:32, crtime: 2024-01-05 10:00:00. The investigator also notes that the file's inode number is 12345. Which of the following is the most accurate interpretation of these timestamps for timeline reconstruction?

An analyst is investigating a compromised Windows Server 2016 system. During timeline analysis, the analyst notices that several executable files in the C:\Windows\Temp directory have $STANDARD_INFORMATION modification times that are earlier than their $FILE_NAME modification times. What is the most likely explanation for this discrepancy?

A forensic analyst is examining a Windows 10 system and wants to build a comprehensive file system timeline. The analyst has already parsed the $MFT and USN journal. Which TWO additional artifacts should the analyst incorporate to most effectively correlate file system events with user and system activity? (Choose two.)

A forensic analyst is examining an NTFS volume and observes that a file's $STANDARD_INFORMATION modification timestamp is 2023-08-15 14:00:00, while its $FILE_NAME modification timestamp is 2023-08-10 09:30:00. The file is a spreadsheet that the user claims was last edited on August 10. Which of the following best explains this discrepancy?

An analyst is examining an NTFS volume and finds that the $MFT record for a file shows a $STANDARD_INFORMATION modification time of 2024-03-10 08:00:00, but the $FILE_NAME modification time is 2024-03-09 22:00:00. The file's content is known to have been modified only once. Which of the following best explains this discrepancy?

An investigator is analyzing a Windows system and finds that a suspicious file has an NTFS $STANDARD_INFORMATION creation time of 2023-05-01 09:00:00, but the $FILE_NAME creation time is 2023-05-01 08:55:00. The file's $LogFile entries show that the file was created at 2023-05-01 08:50:00. Which timestamp is most likely the true creation time of the file?

An analyst is examining a timeline from a Windows 10 system and notices that a file's $FN creation timestamp is significantly earlier than its $SI creation timestamp. The file is located in a directory that was recently moved from another volume. What is the most likely explanation for this discrepancy?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Introduction to File System Timeline Forensics sessions

Start a Introduction to File System Timeline Forensics only practice session

Every question in these sessions is drawn from the Introduction to File System Timeline Forensics domain — nothing else.

Related practice questions

Related GCFA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCFA exam test about Introduction to File System Timeline Forensics?
You must be able to build a MACB file system timeline and correctly interpret each timestamp's meaning and reliability. The most important thing is knowing which timestamps are trustworthy versus user-modifiable, and filtering super-timeline output before drawing conclusions.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Introduction to File System Timeline Forensics questions in a focused session?
Yes — the session launcher on this page draws every question from the Introduction to File System Timeline Forensics domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCFA topics?
Use the topic links above to move to related areas, or go back to the GCFA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCFA exam covers. They are not copied from any real exam or dump site.