Courseiva

CCNA Ntfs Artifact Analysis Questions

37 questions · Ntfs Artifact Analysis topic · All types, answers revealed

1
Multi-Selectmedium

A forensic analyst is examining an NTFS volume and needs to identify which artifacts can provide evidence of file deletion or file system changes that occurred after a file was removed. Which TWO of the following NTFS artifacts are most directly useful for this purpose? (Choose two.)

Select 2 answers
A.$UsnJrnl:$J, which logs file system events including FILE_DELETE and CLOSE reasons.
B.$Volume, which contains the volume label and version information and can indicate volume format changes.
C.$Bitmap, which tracks cluster allocation and can show clusters freed after a file deletion.
D.$AttrDef, which defines valid attribute types and can show when new attributes were added.
E.$Boot, which stores the volume boot sector and can indicate when the volume was last mounted.
AnswersA, C

The USN change journal records events with reason flags, including FILE_DELETE, which indicates a file was deleted. Each record includes the file reference number and timestamp, allowing analysts to correlate deletion events with other activity. This directly supports determining when and possibly how a file was removed.

Why this answer

$Bitmap tracks cluster allocation and can show clusters freed by deletion, while $UsnJrnl:$J logs file system events including FILE_DELETE with timestamps and file references. Together they help identify deleted files and the timing of deletions, making them the most directly useful artifacts among the listed metadata files.

Exam trap

The trap here is confusing general NTFS metadata files with event-logging artifacts, when only $Bitmap and the USN journal provide direct evidence of deletion and post-deletion changes.

2
MCQhard

A forensic analyst is investigating a system where a user is suspected of using a tool to hide files by manipulating NTFS metadata. The analyst finds an MFT entry with a $FILE_NAME attribute that has a namespace value of 2 (POSIX) and a $STANDARD_INFORMATION attribute with timestamps that are inconsistent with the file's $UsnJrnl records. Which conclusion is most appropriate regarding the file's naming and timestamp artifacts?

A.The POSIX namespace indicates the file was created by a POSIX-compliant application, and the timestamp inconsistency is likely due to time zone differences.
B.The POSIX namespace is used for files that are encrypted with EFS, and the timestamp inconsistency indicates the file was recently decrypted.
C.The POSIX namespace suggests the file name contains characters that are not allowed in the Win32 namespace, and the timestamp inconsistency may indicate the file was moved or its timestamps were altered.
D.The POSIX namespace indicates the file is a hard link, and the timestamp inconsistency is due to the link being created at a different time than the original file.
AnswerC

The POSIX namespace is used when a file name contains characters that are valid in POSIX but not in Win32, such as trailing spaces or periods. Such names can be used to hide files. The timestamp inconsistency between $STANDARD_INFORMATION and $UsnJrnl records suggests that the $STANDARD_INFORMATION timestamps may have been altered after the file's creation or last change, which is a common anti-forensic technique.

Why this answer

The POSIX namespace in NTFS is used for file names that are valid in POSIX but not in the Win32 namespace, such as those ending with a space or period. Attackers can use such names to hide files from typical Windows tools. The inconsistency between $STANDARD_INFORMATION timestamps and $UsnJrnl records suggests the $STANDARD_INFORMATION timestamps may have been manipulated, a common anti-forensic technique.

Analysts should correlate these artifacts to detect hidden or altered files.

Exam trap

The trap here is assuming that a POSIX namespace always indicates a benign POSIX application, when it can also be used to create hidden or hard-to-access files on Windows.

3
MCQmedium

What is the consequence of a file name being stored in the $FILE_NAME attribute but not in the $INDEX_ROOT of its parent directory?

A.The file is encrypted with BitLocker.
B.The file is a system-hidden file.
C.The file is an orphaned file.
D.The file is a compressed sparse file.
AnswerC

A file is orphaned when its MFT record still exists, but the corresponding entry in the parent directory's index is missing or corrupted. This prevents the file from being visible in file explorers, making it a target for forensic recovery as it is essentially 'lost' to the OS.

Why this answer

If a file name exists in the $FILE_NAME attribute but not in the parent directory's $INDEX_ROOT, the file is 'orphaned'. It remains present on the disk in the MFT but is invisible to the OS and users via standard directory navigation. This is a common indicator of a partially successful deletion or a file system error that removed the directory link.

Exam trap

Examinees often confuse 'orphaned' files with 'allocated' or 'resident' files, forgetting that missing parent directory index entries disconnect the file from the directory tree.

4
MCQmedium

A forensic analyst is reviewing a Windows 10 workstation suspected of unauthorized data staging. While parsing the Master File Table with a commercial forensic suite, the analyst observes that a suspicious .zip file's $STANDARD_INFORMATION timestamps differ from its $FILE_NAME timestamps by more than six months, and the $FILE_NAME timestamps are older. Which conclusion is most consistent with this artifact pattern?

A.The file was created on a different NTFS volume and later copied onto this workstation using a tool that preserves $FILE_NAME timestamps.
B.The file was accessed by a backup application that updates only $STANDARD_INFORMATION timestamps during incremental backups.
C.The $STANDARD_INFORMATION timestamps were likely altered by a timestomping utility, while the $FILE_NAME timestamps retained the original values.
D.The file system is corrupt and the $FILE_NAME attribute should be treated as unreliable, so only the $STANDARD_INFORMATION timestamps should be used for the timeline.
AnswerC

Timestomping tools such as SetMace or PowerShell's Set-ItemProperty modify $STANDARD_INFORMATION because it is easily writable through the Windows API, but they frequently fail to update $FILE_NAME timestamps, which are only set during file creation or renaming. A large discrepancy where $FILE_NAME is older is a classic indicator of anti-forensic timestamp manipulation on NTFS.

Why this answer

NTFS stores two independent timestamp sets per file: $STANDARD_INFORMATION, writable through normal APIs, and $FILE_NAME, set at creation and rename. Anti-forensic tools commonly change only the former, producing a divergence where $FILE_NAME timestamps are older. This pattern is a reliable indicator of timestomping and should prompt deeper timeline analysis.

Exam trap

The trap here is assuming that matching timestamps confirm authenticity or that any mismatch indicates corruption, when in fact a systematic mismatch between attribute sets is the recognized timestomping signature.

5
MCQmedium

Which NTFS metadata attribute is responsible for storing Security Descriptors (ACLs)?

A.$FILE_NAME
B.$SECURITY_DESCRIPTOR
C.$ATTRIBUTE_LIST
D.$DATA
AnswerB

The $SECURITY_DESCRIPTOR attribute is specifically dedicated to storing the ACLs for a file. It defines the owner, the group, and the permissions granted to various users, which is essential for understanding the access control landscape of the system during a forensic investigation into unauthorized activity.

Why this answer

The $SECURITY_DESCRIPTOR attribute contains the Access Control List (ACL) information for a file, which determines which users or groups can access it. Forensic analysts frequently examine this to identify if permissions have been modified to allow unauthorized access or if a sensitive file has had its permissions altered to hide it from standard administrative users on the system.

Exam trap

Candidates often guess standard data attributes like $DATA or file name attributes instead of looking specifically for security and access control structures.

6
MCQmedium

What does a non-resident $DATA attribute indicate in an NTFS MFT record?

A.The file is too small to be resident.
B.The file data is stored in separate clusters.
C.The file is corrupted.
D.The file is permanently deleted.
AnswerB

A non-resident attribute means the data is located outside the MFT record in physical data clusters. The attribute header contains 'data runs' that describe the starting cluster and the number of clusters occupied, which are essential for manual file carving and data reconstruction.

Why this answer

A non-resident $DATA attribute indicates that the actual file content is stored in external data clusters on the disk, rather than inside the MFT record. This is the standard behavior for most files. Analysts must understand this to correctly use data runs, which are pointers found within the $DATA attribute that tell the OS exactly where to find the file's fragmented pieces on the physical media.

Exam trap

Candidates frequently confuse non-resident attributes with deleted files, assuming that non-resident status implies data loss or file corruption rather than standard storage in external clusters.

7
MCQeasy

Which NTFS attribute would an investigator primarily examine to determine the parent directory of a specific file?

A.$STANDARD_INFORMATION
B.$FILE_NAME
C.$DATA
D.$INDEX_ROOT
AnswerB

$FILE_NAME stores the name of the file and, crucially, the reference ID of its parent directory. This allows the OS to construct the file path and navigate the directory tree. Analysts use this to verify the file's location and identify potential discrepancies with the user-provided path.

Why this answer

The $FILE_NAME attribute contains the parent directory ID, which is a reference to the directory's record in the MFT. This attribute is essential for building a full path for a file. Because it is maintained by the system kernel, it is also highly reliable for verification against the user-visible paths provided by the $SI attribute, aiding in identifying path-based manipulation.

Exam trap

Test-takers often incorrectly choose the $INDEX_ROOT or $STANDARD_INFORMATION attribute when asked to find the parent directory reference for a specific file.

8
MCQhard

An investigator is examining an NTFS volume from a system that was abruptly powered off during a malware installation. The analyst observes that the MFT contains a file record for a suspicious executable with a valid $DATA attribute, but the file is not visible in the directory index. Which NTFS artifact should the analyst examine to determine whether the file record was orphaned due to an interrupted transaction?

A.The $Secure:$SDS stream, which stores security descriptors and would show if the file's permissions were applied during creation.
B.The $UsnJrnl:$J, which records all file system changes and would show the file creation event even if the directory index was not updated.
C.The $Bitmap, which tracks cluster allocation and would indicate whether the file's clusters were allocated before the power loss.
D.The $LogFile, which contains redo and undo records that can show incomplete metadata transactions from the power loss.
AnswerD

$LogFile is a write-ahead log that records metadata transactions before they are committed to the MFT. After a power loss, it can contain redo and undo records for incomplete operations, such as a file creation that updated the MFT but not the parent directory index. Examining $LogFile can reveal whether the orphaned record resulted from an interrupted transaction.

Why this answer

$LogFile is the NTFS write-ahead journal that ensures metadata consistency. It records redo and undo information for transactions. After an abrupt power loss, incomplete transactions may leave the MFT updated but the directory index not, producing an orphaned file record.

Analyzing $LogFile can reveal the interrupted operation and help reconstruct the intended state.

Exam trap

The trap here is assuming the USN journal or $Bitmap can explain transaction interruption, when only $LogFile contains the redo/undo records needed to analyze incomplete metadata operations.

9
MCQeasy

Which NTFS metadata file serves as the index for all files and directories on the volume?

A.$MFT
B.$LogFile
C.$Boot
D.$Volume
AnswerA

The $MFT file is the primary repository for all file metadata. It stores the file name, size, permissions, and data location for every object on the volume. Without the $MFT, the operating system would be unable to locate or manage files, and forensic analysis would be severely hindered.

Why this answer

The Master File Table (MFT) is the central database of an NTFS volume. Every file and directory on the disk has at least one entry in the MFT. Understanding the MFT is the foundation of NTFS forensics, as it contains all the metadata necessary to identify file properties, permissions, and data locations, which are essential for rebuilding the state of the filesystem during an investigation.

Exam trap

Candidates often confuse the Master File Table ($MFT) with individual file records or system logs like $LogFile, failing to recognize that the $MFT itself is the root database indexing every file and directory.

10
MCQmedium

What is the primary purpose of the $LogFile in NTFS?

A.To track user login history.
B.To prevent filesystem corruption.
C.To store backup copies of files.
D.To record all file access logs.
AnswerB

The $LogFile ensures atomic updates to metadata. By logging transactions before applying them, the NTFS driver can restore the volume to a consistent state following an unexpected power loss or system failure, which is the core requirement for modern, reliable file system operation.

Why this answer

The $LogFile is essential for maintaining NTFS consistency. It records all metadata changes before they are committed, allowing the system to recover from crashes by rolling back or completing interrupted operations. While the $LogFile is circular and does not store user data, its entries can often reveal the order of operations, helping an investigator reconstruct the sequence of events leading up to a system compromise.

Exam trap

Candidates often assume the $LogFile is intended for user activity tracking or auditing, failing to recognize its technical purpose as a filesystem consistency mechanism for crash recovery.

11
MCQeasy

Which NTFS master file table (MFT) record contains metadata about the MFT itself?

A.MFT Record 0
B.MFT Record 1
C.MFT Record 5
D.MFT Record 255
AnswerA

Record 0 is defined in the NTFS specification as the $MFT. It stores the metadata entries for the file system structure itself. This enables the operating system to bootstrap the driver and understand the layout of all subsequent files, directories, and internal system structures stored on the volume.

Why this answer

In NTFS, the MFT is treated as a file, and its metadata is stored within its own entry. Record 0 is reserved specifically for the MFT. This recursive structure is fundamental to the NTFS architecture, allowing the system to locate the MFT at boot time and parse the rest of the file system efficiently during startup processes.

Exam trap

Test-takers often guess record 1 or record 5, confusing the root directory or standard system files with the actual MFT metadata record itself.

12
Multi-Selecthard

An examiner is analyzing an NTFS volume from a Windows Server 2016 system that was abruptly powered off during a security incident. The examiner wants to determine recent file system changes that may not have been flushed to the $MFT. Which two NTFS artifacts should the examiner prioritize to reconstruct recent metadata operations? (Choose two.)

Select 2 answers
A.$LogFile
B.$UsnJrnl
C.$Secure
D.$Bitmap
E.$Boot
AnswersA, B

$LogFile records metadata transactions before they are committed to the $MFT. After a sudden power loss, it can contain recent file creation, deletion, and renaming operations that were not yet flushed. Parsing it allows reconstruction of file system changes that occurred just before the crash.

Why this answer

$LogFile and $UsnJrnl both record metadata operations. $LogFile is a write-ahead log that captures transactions before they are committed to the $MFT, making it valuable after an unexpected shutdown. $UsnJrnl provides a persistent change journal that records file and directory modifications. Together they can reconstruct recent activity that may not be present in the $MFT.

Exam trap

The trap here is assuming that allocation maps like $Bitmap or security files like $Secure contain change history, when only $LogFile and $UsnJrnl record metadata operations.

13
MCQhard

An analyst is examining an NTFS volume from a Windows Server 2019 system that was used as a file server. A file critical to the investigation is missing from the directory listing, but the analyst suspects the file was recently deleted and its MFT entry has not been overwritten. Which NTFS artifact should the analyst examine to recover the file's full path and name if the MFT entry is still intact?

A.$UsnJrnl:$J stream
B.$FILE_NAME attribute within the file's MFT record
C.$INDEX_ROOT attribute of the parent directory
D.$Bitmap metadata file
AnswerB

The $FILE_NAME attribute in an MFT record stores the file's name and a reference to the parent directory's MFT entry. Even after deletion, if the MFT record is not overwritten, this attribute remains and can be used to reconstruct the full path by following the parent reference. This is the primary artifact for recovering the name and location of a deleted file when the MFT entry is intact.

Why this answer

The $FILE_NAME attribute in the MFT record contains the file's name and a reference to its parent directory's MFT entry. By parsing this attribute and then locating the parent MFT entry, an analyst can reconstruct the full path. Other artifacts like $Bitmap or $UsnJrnl may provide supporting information but do not directly contain the full path.

Exam trap

The trap here is assuming that the USN Journal or $Bitmap contains the full path, when in fact the $FILE_NAME attribute in the MFT record is the authoritative source for the file's name and parent reference.

14
MCQhard

What is the primary function of the $ATTRIBUTE_LIST attribute in an MFT entry?

A.To index directory contents.
B.To store extended file permissions.
C.To reference attributes stored in other MFT records.
D.To track file deletion history.
AnswerC

When a file's attributes exceed the size of one MFT record, the $ATTRIBUTE_LIST attribute is created. It acts as a pointer map, listing the location and type of attributes held in additional MFT records, ensuring that the operating system can still access the complete metadata set for the file.

Why this answer

The $ATTRIBUTE_LIST attribute is used when an MFT record is too small to hold all of a file's attributes. By storing a list of references to other MFT records, NTFS allows a single file to span multiple records. This is a crucial concept for analysts because it means that critical evidence, such as timestamps or data runs, might be hidden in secondary MFT records outside the primary entry.

Exam trap

Candidates often assume an MFT record is always self-contained, failing to account for the $ATTRIBUTE_LIST which allows files to span multiple MFT records when metadata is too large.

15
Multi-Selecthard

You are analyzing an NTFS volume and need to determine the original path and name of a file that has been moved to a different directory. The file's MFT entry contains multiple $FILE_NAME attributes. Which two of the following statements about $FILE_NAME attributes are correct? (Choose two.)

Select 2 answers
A.The $FILE_NAME attribute stores the file's original path when the file was moved, and the parent directory reference points to the original directory.
B.The $FILE_NAME attribute includes a namespace field that indicates whether the name is in the POSIX, Win32, or DOS namespace.
C.Each $FILE_NAME attribute corresponds to a hard link to the file, and the parent directory reference points to the directory containing that link.
D.The $FILE_NAME attribute is updated whenever the file's content is modified, reflecting the last modification time.
E.The $FILE_NAME attribute can be resident or non-resident depending on the length of the filename.
AnswersB, C

The $FILE_NAME attribute has a namespace field that specifies the naming convention: POSIX (0), Win32 (1), DOS (2), or Win32 & DOS (3). This field helps determine the format of the filename, such as whether it is a short 8.3 name or a long name. It is a standard part of the attribute.

Why this answer

$FILE_NAME attributes represent hard links; each link has a parent directory reference pointing to the directory containing the link. The namespace field indicates the naming convention used. These attributes are always resident and their timestamps update on rename or move, not content modification.

Multiple $FILE_NAME attributes therefore indicate multiple hard links, and their parent references help reconstruct directory structure.

Exam trap

The trap here is assuming that $FILE_NAME attributes preserve historical paths or that they are updated on content modification, when they actually reflect current hard links and static timestamps.

16
MCQmedium

What is the significance of the $LogFile in NTFS when performing an investigation on a system that experienced a sudden power loss?

A.It stores user credentials for encrypted sessions.
B.It records transaction metadata for crash recovery.
C.It keeps a copy of all deleted file contents.
D.It is used by BitLocker to verify volume integrity.
AnswerB

The $LogFile ensures that NTFS can recover from crashes by logging metadata transactions. Investigators can parse this to see recent file system changes that were in progress. This makes it a high-value artifact for reconstructing activity that occurred immediately preceding a system crash or intentional shutdown.

Why this answer

The $LogFile is a circular buffer that records metadata operations before they are finalized. When a system crashes or loses power, the NTFS driver uses the $LogFile upon reboot to replay or undo incomplete transactions, ensuring volume consistency. For investigators, it provides a window into the state of the filesystem immediately before the crash, potentially recovering records of files modified just before the power failure.

Exam trap

Candidates often confuse the $LogFile with the Event Logs or the USN Journal, mistakenly assuming it contains application-level activity logs rather than low-level filesystem transaction metadata used for crash recovery.

17
MCQeasy

What is the primary role of the $MFTMirr file in NTFS?

A.To mirror all file contents.
B.To index all files in the system.
C.To provide a backup of the first MFT records.
D.To store encrypted file keys.
AnswerC

The $MFTMirr file acts as a protective mechanism, storing a copy of the first few entries in the MFT. This allows the system to recover essential boot and file system metadata if the beginning of the MFT is corrupted, ensuring the volume remains accessible for basic operations.

Why this answer

The $MFTMirr file contains a backup of the first few records of the Master File Table. This is vital for filesystem recovery if the primary MFT record gets corrupted. For forensic analysts, the $MFTMirr provides a fail-safe that confirms the structure of the MFT and can sometimes contain remnants of file metadata that are useful when the primary MFT record has been damaged or maliciously altered.

Exam trap

Students frequently mistake the $MFTMirr for a full backup of the entire filesystem rather than realizing it is specifically a safety copy of only the first few MFT records.

18
MCQmedium

An analyst is examining a Windows 10 system where a user deleted several files containing sensitive data. The analyst needs to recover the file content and determines that the $DATA attribute of the MFT record for one deleted file is resident. What does this indicate about the file's data and its recoverability?

A.The file content is stored in clusters outside the MFT and can be recovered by carving the volume
B.The file content is stored within the MFT record itself and may be recoverable if the record has not been overwritten
C.The file content is compressed and requires the $COMPRESSION attribute to be decoded
D.The file content is encrypted and requires the $LOGGED_UTILITY_STREAM attribute to be decrypted
AnswerB

A resident $DATA attribute means the file's content is small enough to fit inside the MFT record. When the file is deleted, the record is marked as free but the data remains until the record is reallocated. Therefore, the content may still be recoverable by parsing the MFT entry.

Why this answer

A resident $DATA attribute means the file's content is stored directly within the MFT record because it is small enough. After deletion, the record is marked free but the data persists until the record is reused. An examiner can parse the MFT entry to recover the content, provided the record has not been overwritten.

Exam trap

The trap here is confusing resident data with external cluster storage, leading an analyst to attempt carving instead of examining the MFT record itself.

19
MCQhard

During an investigation, you recover a deleted file from an NTFS volume. The MFT entry for the file shows that the $DATA attribute is non-resident, and the data runs are still intact. However, the $BITMAP attribute of the MFT indicates that the MFT entry is marked as unallocated. What is the most accurate conclusion about the recoverability of the file's content?

A.The file content is likely recoverable, but you must check the $Bitmap metadata file to confirm the clusters are not reallocated.
B.The file content is unrecoverable because the MFT entry is unallocated, which means the data runs are invalid.
C.The file content can be fully recovered because the data runs are intact and point to clusters that have not been overwritten.
D.The file content can be recovered only if the $LogFile contains a record of the file's deletion.
AnswerA

The $Bitmap file tracks cluster allocation. Even if the MFT entry is unallocated, the clusters may still be free. Checking $Bitmap confirms whether the data runs point to allocated clusters. If the clusters are free, recovery is likely; if allocated, the content may be partially or fully overwritten.

Why this answer

When an MFT entry is unallocated, the file's data runs may still be present, but the clusters they point to could have been reallocated. The $Bitmap metadata file tracks which clusters are in use. To determine recoverability, the analyst must check whether the clusters are marked as free in $Bitmap.

If free, the content can likely be recovered; if allocated, the content may be overwritten.

Exam trap

The trap here is equating an unallocated MFT entry with unrecoverable data, overlooking that cluster allocation status is the decisive factor for content recovery.

20
MCQeasy

An analyst is examining an NTFS volume and wants to identify the MFT entry for a specific file named 'report.docx'. The analyst knows the file's path but needs to locate its MFT record number to examine its attributes. Which NTFS metadata file should the analyst consult to map the file path to its MFT record number?

A.$Index allocation attributes within directory entries
B.$Bitmap
C.$MFT
D.$Root
AnswerA

NTFS directories store index entries in $INDEX_ROOT and $INDEX_ALLOCATION attributes. These entries map file names to their MFT record numbers. By traversing the directory hierarchy, an examiner can resolve the full path to the file's MFT record number. This is the correct method for path-to-record resolution.

Why this answer

To map a file path to its MFT record number, an examiner must traverse the directory index structures. Directories in NTFS use $INDEX_ROOT and $INDEX_ALLOCATION attributes to store entries that associate file names with MFT record numbers. Starting from the root directory and following each path component leads to the target file's record.

Exam trap

The trap here is assuming that $MFT or $Bitmap can directly resolve a file path, when only directory index attributes contain the name-to-record mapping.

21
MCQmedium

During a forensic analysis, you encounter a file with a 'resident' $DATA attribute. What does this mean for your data recovery process?

A.The file is fragmented across multiple clusters.
B.The file data is stored directly in the MFT record.
C.The file is encrypted with EFS.
D.The file is hidden from standard Windows APIs.
AnswerB

Resident data is stored within the MFT record itself, avoiding the need for cluster allocation. This is an optimization for small files (typically under 700-900 bytes). For forensic analysts, this means the file content is immediately available once the MFT record is parsed, without needing cluster map traversal.

Why this answer

A resident $DATA attribute means the file content is stored directly within the MFT record rather than in external clusters. This is common for very small files. Because the data is already inside the MFT record, you do not need to parse data runs or follow cluster pointers to extract the file, significantly simplifying the recovery process for small configuration or text files.

Exam trap

Students frequently mistake resident attributes for compressed files or think they require external data runs and cluster mapping to extract the content.

22
MCQeasy

A forensic analyst is reviewing an NTFS volume and notices that a particular file has an $ATTRIBUTE_LIST attribute in its MFT record. What does the presence of this attribute indicate about the file?

A.The file has multiple $DATA attributes, indicating alternate data streams.
B.The file is compressed, and the $ATTRIBUTE_LIST contains the compression unit size.
C.The file's attributes are spread across multiple MFT records because they do not fit in a single record.
D.The file is encrypted with EFS, and the $ATTRIBUTE_LIST stores encryption keys.
AnswerC

The $ATTRIBUTE_LIST attribute is used when a file's attributes exceed the space available in a single MFT record. It lists the attributes and their locations, which may be in additional MFT records. This allows NTFS to manage files with many attributes or large attributes that cannot be stored in one record. This is the primary purpose of the $ATTRIBUTE_LIST.

Why this answer

The $ATTRIBUTE_LIST attribute is present when a file's attributes cannot fit in a single MFT record. It enumerates the attributes and their locations, which may be in additional MFT records. This is common for files with many attributes or large attributes like long $DATA runs or numerous alternate data streams.

Its presence indicates that the file's metadata is distributed across multiple MFT records.

Exam trap

The trap here is confusing $ATTRIBUTE_LIST with attributes that indicate specific features like encryption or compression, when it is actually a structural mechanism for managing attribute overflow.

23
MCQhard

An investigator is analyzing an NTFS volume from a compromised server. A file named 'payroll.xlsx' appears in the directory listing, but the MFT record for that filename shows a zero-length $DATA attribute and no $OBJECT_ID. A separate MFT record with a different record number contains the same $FILE_NAME value, a large non-resident $DATA attribute, and an $OBJECT_ID. Which NTFS artifact best explains the presence of two MFT records referencing the same filename?

A.A hard link was created, so the original MFT record was repurposed while a new record was allocated for the additional filename reference.
B.The volume is part of a Distributed File System replica, and DFSR metadata duplicated the MFT record during replication.
C.The file was deleted and later a new file with the same name was created, leaving a stale MFT record alongside the active one.
D.The file was compressed, causing NTFS to create a shadow MFT record for the compressed data stream.
AnswerC

When a file is deleted, its MFT record is marked inactive but not immediately wiped; a new file with the same name receives a different record number. The stale record may retain a zero-length $DATA or residual attributes, while the new record holds the active data and an $OBJECT_ID assigned at creation, explaining the duplicate filename across two records.

Why this answer

NTFS does not immediately clear MFT records when files are deleted; the record is marked unallocated but its contents may persist until reused. A subsequent file with the same name is assigned a new record number, producing two records with the same $FILE_NAME. The active record typically contains the live $DATA and an $OBJECT_ID, while the stale record may show remnants such as zero-length data.

Exam trap

The trap here is assuming that a filename uniquely identifies an MFT record, when in fact NTFS can retain stale records for deleted files that share names with active files.

24
MCQeasy

An analyst is examining an NTFS volume and finds a file named 'confidential.docx' in a directory. The file's MFT record shows that the $DATA attribute is resident. What does this indicate about the file's data storage, and what is the primary forensic implication?

A.The file's content is encrypted with EFS, and the resident $DATA attribute stores the encryption keys.
B.The file's content is stored entirely within the MFT record, and the analyst can recover it directly from the MFT without carving the disk.
C.The file's content is stored in clusters outside the MFT, and the analyst must use the data runs to locate it on disk.
D.The file's content is compressed and stored in the MFT record, requiring decompression before analysis.
AnswerB

A resident $DATA attribute means the file's content is small enough to fit within the MFT record, typically under approximately 700 bytes. The data is stored directly in the MFT entry, so the analyst can extract it by parsing the MFT record. This is a straightforward recovery because no cluster allocation or disk carving is required.

Why this answer

A resident $DATA attribute indicates that the file's content is small enough to be stored directly within the MFT record. This means the analyst can recover the file content by parsing the MFT entry, without needing to locate clusters on disk. It is a simpler recovery scenario than non-resident data, which requires following data runs to clusters.

Exam trap

The trap here is confusing resident $DATA with non-resident $DATA, or assuming that resident data implies compression or encryption when it simply means the data fits in the MFT record.

25
MCQmedium

An analyst is examining the USN Journal. What is the primary purpose of this file in the context of NTFS forensic analysis?

A.Storing encrypted file passwords.
B.Providing a history of file system changes.
C.Maintaining the B-tree structure of directories.
D.Tracking user login and logout sessions.
AnswerB

The USN Journal logs every change made to files and directories on the volume. By parsing this file, investigators can reconstruct a timeline of events even if the original files were deleted. It is a critical artifact for understanding the sequence of events during a security incident.

Why this answer

The USN Journal ($UsnJrnl) provides a chronological log of all changes made to files and directories on an NTFS volume. For forensics, it is invaluable because it captures activity that may no longer be reflected in the current MFT, such as the creation and subsequent deletion of files, or directory renames, providing a persistent history of disk modifications for timeline reconstruction.

Exam trap

Many analysts mistakenly believe the USN Journal is a security log for user actions, failing to identify that it is a filesystem-level log of all changes to metadata.

26
Multi-Selectmedium

A forensic analyst is examining an NTFS volume and needs to determine whether a specific file was recently deleted and whether its data clusters have been reallocated. The analyst has access to the MFT, the $Bitmap metadata file, and the $UsnJrnl. Which two artifacts should the analyst correlate to confirm that the file's MFT record is unallocated and that its clusters are now marked as free? (Choose two.)

Select 2 answers
A.The in-use flag in the file's MFT record header, which indicates whether the record is allocated or unallocated.
B.The $Bitmap metadata file, which tracks the allocation status of clusters on the volume.
C.The $Secure metadata file, which contains security descriptors and can indicate whether the file was protected from deletion.
D.The $LogFile, which records all metadata transactions and can show the exact deletion operation.
E.The $UsnJrnl, which records file system changes including deletions and can provide a timestamp for the deletion event.
AnswersA, B

The MFT record header contains an in-use flag that NTFS sets to 0 when a file is deleted, marking the record as unallocated. This is a primary indicator that the file no longer exists in the active file system. The analyst can parse this flag directly from the MFT record to confirm the file's deletion state, independent of other metadata.

Why this answer

To confirm that a file's MFT record is unallocated and its clusters are free, the analyst should check the in-use flag in the MFT record header and the corresponding bits in the $Bitmap file. The in-use flag directly indicates whether the record is allocated, while the $Bitmap tracks cluster allocation across the volume. Together they provide definitive evidence of deletion and cluster reallocation status.

Exam trap

The trap here is assuming that the $UsnJrnl or $LogFile can confirm cluster reallocation, when only the $Bitmap tracks current cluster allocation status.

27
MCQmedium

A forensic analyst is examining an NTFS volume and finds that a directory's $I30 index entries are present in the $INDEX_ROOT, but the $INDEX_ALLOCATION attribute is non-resident and points to INDX records. The analyst needs to determine whether a deleted file once existed in that directory. Which artifact should the analyst examine to find residual filename entries that may reference the deleted file?

A.Slack space within the INDX records in the $INDEX_ALLOCATION
B.The $REPARSE_POINT attribute in the directory's MFT record
C.The $LOGGED_UTILITY_STREAM attribute of the directory
D.The $BITMAP attribute of the directory's MFT record
AnswerA

INDX records in the $INDEX_ALLOCATION contain index entries and often retain stale or slack entries after a file is deleted. These residual entries can include the filename and file reference of a deleted file. Analyzing the slack space of these INDX records is a standard technique to recover evidence of deleted files from a directory index.

Why this answer

When a file is deleted from an NTFS directory, its entry in the $I30 index is removed, but remnants often persist in the slack space of INDX records within the $INDEX_ALLOCATION. These residual entries can contain the filename and file reference number, allowing an analyst to infer the existence of a deleted file. The $BITMAP, $LOGGED_UTILITY_STREAM, and $REPARSE_POINT attributes do not store filename entries.

Exam trap

The trap here is assuming that deleted directory entries are completely erased and that only the $MFT can show deleted files, overlooking the residual data in INDX slack space.

28
MCQhard

Which attribute is used to store the location and length of file data runs in an NTFS MFT record?

A.$FILE_NAME
B.$DATA
C.$INDEX_ROOT
D.$ATTRIBUTE_LIST
AnswerB

$DATA contains either the data itself (if resident) or the data runs (if non-resident). Data runs provide the logical-to-physical mapping required for the OS to retrieve file data from the disk clusters. This is the core attribute for mapping file content to disk-level storage locations.

Why this answer

The $DATA attribute is responsible for storing the file's content or references to the clusters where the data resides on the disk. When the file is too large to be resident, the $DATA attribute contains 'data runs'—compacted descriptions of the starting cluster and the number of consecutive clusters allocated to the file, which the driver uses to read the file data.

Exam trap

Candidates frequently confuse the $DATA attribute with $STANDARD_INFORMATION or $FILE_NAME when asked where non-resident file data runs and cluster locations are stored.

29
MCQeasy

A forensic analyst is reviewing an NTFS volume and notices that a particular MFT record has an $ATTRIBUTE_LIST attribute. The analyst wants to understand why this attribute is present. Which of the following best describes the purpose of the $ATTRIBUTE_LIST attribute in an MFT record?

A.It stores the security descriptor for the file to control access permissions.
B.It lists the data runs for the $DATA attribute when the file is fragmented.
C.It tracks the change journal entries for the file for auditing purposes.
D.It provides a mapping of all attributes and their locations when they do not fit in the base MFT record.
AnswerD

The $ATTRIBUTE_LIST attribute is used when a file has many attributes or large attributes that cannot fit in the base MFT record. It lists the attributes and indicates whether they are resident in the base record or in an extension MFT record. This allows NTFS to locate all attributes of a file across multiple MFT records.

Why this answer

The $ATTRIBUTE_LIST attribute is present when a file's attributes cannot all fit in the base MFT record. It lists each attribute and specifies whether it is resident in the base record or in an extension record, along with the MFT reference of that extension record. This allows NTFS to locate all attributes.

The other options describe functions of other attributes or metadata files.

Exam trap

The trap here is confusing the $ATTRIBUTE_LIST with attributes that store data runs or security information, when it actually serves as an index for locating attributes across MFT records.

30
MCQhard

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is non-resident, but the file size reported by the operating system is 0 bytes. The analyst suspects the file may have been involved in a data hiding technique. Which of the following is the most likely explanation for this discrepancy?

A.The file is a sparse file, and the 0-byte size indicates that all its data is stored in sparse regions.
B.The file's data runs point to clusters that have been marked as bad and are no longer accessible.
C.The file's $DATA attribute has a logical size of 0 but still has allocated clusters, indicating possible slack space or hidden data.
D.The $DATA attribute is corrupted, and the file system is reporting an incorrect size.
AnswerC

In NTFS, a non-resident $DATA attribute can have a logical size of 0 while still having allocated clusters if the file was truncated or if data was written and then the size was reset without deallocating clusters. This can be used to hide data in allocated clusters that are not reflected in the file size. Forensic tools can examine the data runs to recover such hidden data.

Why this answer

A non-resident $DATA attribute with a logical size of 0 but allocated clusters is a classic sign of data hiding. An attacker can write data to a file, then truncate the file's logical size to 0 without deallocating the clusters, leaving the data intact in the allocated clusters. Forensic tools can parse the data runs and recover the hidden content.

This technique is often used to conceal data on NTFS volumes.

Exam trap

The trap here is assuming that a 0-byte file size means no data exists, when in fact allocated clusters may still contain hidden data.

31
MCQeasy

A first responder is collecting volatile and non-volatile data from a running Windows Server 2019 system. The investigator needs to determine which user or process most recently renamed a specific file on an NTFS volume, but the $STANDARD_INFORMATION timestamps show only a modification time. Which NTFS artifact should the investigator query to find rename events that record the previous filename?

A.The $UsnJrnl:$J alternate data stream, which logs USN_RECORD entries including RENAME_OLD_NAME and RENAME_NEW_NAME reasons.
B.The $MFT's $FILE_NAME attribute, which stores a history of all previous names assigned to the file.
C.The $Secure:$SDS stream, which records security descriptor changes that occur during rename operations.
D.The $LogFile, which contains redo and undo records for all metadata transactions including filename changes.
AnswerA

The USN change journal records file system events with reason flags such as RENAME_OLD_NAME and RENAME_NEW_NAME, and each record includes the filename at the time of the event. Querying $UsnJrnl:$J can reveal the prior name and the sequence of renames, which the $STANDARD_INFORMATION timestamps alone cannot show.

Why this answer

The USN change journal, stored in the $UsnJrnl:$J alternate data stream, records file system events with reason codes. RENAME_OLD_NAME and RENAME_NEW_NAME entries capture both the prior and current filenames along with a timestamp and the file reference number. This makes the USN journal the primary artifact for reconstructing rename activity on NTFS.

Exam trap

The trap here is assuming the $LogFile or $MFT retains historical filenames, when only the USN change journal systematically records rename events with old and new names.

32
MCQmedium

What is the primary advantage of the $UsnJrnl over the $LogFile for long-term forensic analysis?

A.It stores full file content for every transaction.
B.It has a much longer retention period.
C.It is not volatile and survives power loss.
D.It contains the actual NTFS security descriptors.
AnswerB

The $UsnJrnl is designed to track volume changes for administrative purposes, leading to a much larger storage capacity compared to the circular, high-frequency $LogFile. This allows analysts to view long-term trends and historical file operations, which is crucial for reconstructive analysis during an incident response engagement.

Why this answer

The $UsnJrnl (Update Sequence Number Journal) is designed to track changes to files and directories over a long period. Unlike the $LogFile, which is a circular, short-term buffer for atomicity and recovery, the $UsnJrnl maintains a more persistent record of file activity. This makes it an invaluable source of historical metadata for investigators tracking how files were modified, created, or deleted over weeks or months.

Exam trap

Candidates often confuse the $UsnJrnl with the $LogFile, assuming both serve the same short-term recovery purpose rather than recognizing the UsnJrnl's long-term persistence advantage.

33
MCQhard

An investigator is analyzing an NTFS volume and finds that a file's $DATA attribute is non-resident and its data runs point to clusters that are currently allocated to a different file. The file's size is 10 KB. What is the most likely explanation for this situation?

A.The file is encrypted, and the data runs are stored in the $EFS attribute instead of $DATA.
B.The file's data runs are corrupt or the MFT entry is inconsistent, possibly due to disk corruption or deliberate manipulation.
C.The file is sparse, and the data runs include sparse ranges that map to clusters not physically allocated.
D.The file is compressed, and the data runs are stored in a separate $DATA attribute named $TXF_DATA.
AnswerB

If a file's non-resident $DATA attribute points to clusters that are currently allocated to another file, this indicates an inconsistency in the file system metadata. This can occur from disk corruption, software bugs, or deliberate tampering. It is not a normal state for any standard NTFS feature.

Why this answer

A non-resident $DATA attribute with data runs pointing to clusters allocated to another file is an abnormal condition. Standard NTFS features like compression, sparse files, or encryption do not cause such overlap. This inconsistency suggests corruption or intentional manipulation, requiring further forensic examination to determine the cause and potential data recovery challenges.

Exam trap

The trap here is attributing the cluster overlap to a standard NTFS feature like compression or sparse files, when it actually indicates metadata corruption or tampering.

34
MCQmedium

An examiner images a Windows 10 workstation and notices that several user profile folders are out of order in the \$MFT when sorted by MFT record number, yet the $STANDARD_INFORMATION timestamps are consistent. The examiner suspects that entries were reordered or that records were freed and reused. Which NTFS artifact best supports determining whether MFT record numbers have been reassigned to different files over time?

A.The $MFT record's sequence number, because it increments each time the record is allocated to a new file
B.The $STANDARD_INFORMATION attribute timestamps, because they are updated on every file access
C.The volume's $Bitmap file, because it tracks the allocation status of every MFT record
D.The $FILE_NAME attribute timestamps, because they persist across record reuse
AnswerA

Each MFT entry contains a sequence number that is incremented every time the record is allocated to a different file. By comparing the sequence number observed at acquisition with earlier journal or log entries, an examiner can determine whether the record number has been reused and how many times.

Why this answer

The sequence number in an MFT file record is the key indicator of record reuse. It increases each time the record is allocated to a new file, so a higher sequence number than expected suggests the original file was deleted and the record was reassigned. Timestamps and $Bitmap do not preserve this allocation history.

Exam trap

The trap here is assuming that timestamp attributes alone can prove MFT record reuse, when only the sequence number records allocation changes.

35
MCQmedium

An analyst discovers a file with a non-zero size but no data in the $DATA attribute. Where is the file content likely located?

A.The $LogFile
B.The $Bitmap
C.The MFT record
D.The $Extend folder
AnswerC

Resident files store their data directly within the MFT record structure when the file size is smaller than the remaining space in the record. This avoids allocating a cluster, effectively keeping the file content embedded within the MFT itself, which forensic analysts must extract directly from the MFT entry.

Why this answer

In NTFS, small files are stored directly within the Master File Table (MFT) record as resident data. This is an optimization to save cluster space and reduce disk I/O. When the data attribute is resident, the content is part of the MFT entry itself, which is critical for investigators to understand when carving data, as standard file-based recovery tools might overlook these resident segments during deep analysis.

Exam trap

Candidates often assume the file must be corrupted or missing data, failing to recognize that small files can be stored 'resident' directly within the MFT record itself.

36
MCQmedium

A forensic analyst is reviewing an NTFS volume from a Windows 10 workstation. The analyst finds an MFT entry whose $STANDARD_INFORMATION attribute contains four timestamps that are all set to a date three years in the past, but the corresponding $FILE_NAME attribute timestamps show dates within the past week. The file's content matches a recently created document. Which conclusion is most strongly supported by this artifact discrepancy?

A.The $STANDARD_INFORMATION timestamps were deliberately altered by a timestomping tool, while the $FILE_NAME timestamps reflect the actual file system activity.
B.The file was copied from an external NTFS volume, which preserved the original $STANDARD_INFORMATION timestamps but updated the $FILE_NAME timestamps.
C.The volume was formatted with a non-default cluster size, which causes $STANDARD_INFORMATION and $FILE_NAME timestamps to be updated independently.
D.The file system journal was replayed after an unclean shutdown, causing the $STANDARD_INFORMATION timestamps to roll back while the $FILE_NAME timestamps were left intact.
AnswerA

Timestomping utilities commonly modify the $STANDARD_INFORMATION timestamps because that is what Windows Explorer and many tools display, but they often overlook the $FILE_NAME attribute timestamps, which are updated by the file system during rename or creation events. The three-year-old values in $STANDARD_INFORMATION versus recent $FILE_NAME values strongly indicate deliberate manipulation of the $STANDARD_INFORMATION timestamps.

Why this answer

The $STANDARD_INFORMATION attribute is the primary target of timestomping tools because it is what most user-facing interfaces display. The $FILE_NAME attribute, which is indexed in the directory entry, is often left unchanged by such tools. A large discrepancy where $STANDARD_INFORMATION is backdated but $FILE_NAME reflects recent activity is a classic indicator of deliberate timestamp manipulation.

Exam trap

The trap here is assuming that any timestamp discrepancy between $STANDARD_INFORMATION and $FILE_NAME automatically proves timestomping, when legitimate operations such as file moves within a volume or certain backup restores can also produce differences.

37
MCQhard

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is resident. The file size is 800 bytes. The analyst attempts to recover the file content using a tool that only reads the data runs from the MFT record. What will be the outcome of this recovery attempt?

A.The tool will recover only the first 800 bytes from the data runs, which are partially resident.
B.The tool will successfully recover the file content because the data is stored in the MFT record.
C.The tool will fail to recover the file content because it does not parse the resident data within the MFT record.
D.The tool will recover the file content from the $ATTRIBUTE_LIST if the resident data overflows the MFT record.
AnswerC

Resident $DATA attributes store the file content directly within the MFT record, not in separate clusters. A tool that only reads data runs is designed for non-resident attributes and will not extract resident data. Thus, the recovery attempt will fail because the tool does not parse the resident data. The content remains in the MFT record but is inaccessible to this tool.

Why this answer

Resident $DATA attributes store file content directly within the MFT record, not in separate clusters. A tool that only reads data runs is designed for non-resident attributes and will not extract resident data. Therefore, the recovery attempt will fail because the tool does not parse the resident data.

The content remains in the MFT record but is inaccessible to this tool.

Exam trap

The trap here is assuming that all file data is stored in data runs, ignoring the fact that small files can have resident $DATA attributes where content is embedded in the MFT record.

Ready to test yourself?

Try a timed practice session using only Ntfs Artifact Analysis questions.