Courseiva

GCFA · topic practice

NTFS Artifact Analysis practice questions

This domain covers how NTFS stores metadata and change history across $MFT, $STANDARD_INFORMATION, $FILE_NAME, $LogFile, and $UsnJrnl. GCFA questions present imaging or live-response scenarios and ask you to identify which artifact proves a rename, creation, deletion, or timestamp inconsistency, and to reason about record ordering and journal retention.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: NTFS Artifact Analysis

What the exam tests

What to know about NTFS Artifact Analysis

Be able to map a rename or deletion to the correct NTFS artifact and justify it with reason codes and timestamps. The single most important thing: know when to trust $UsnJrnl versus $LogFile versus $MFT metadata, and never rely on one timestamp alone.

Interpreting $STANDARD_INFORMATION versus $FILE_NAME timestamp pairs in $MFT records

Using $UsnJrnl reason codes to prove file rename, creation, and deletion events

Distinguishing $LogFile transactional metadata from $UsnJrnl long-term change records

Correlating MFT record numbers, sequence numbers, and out-of-order profile folders

Watch out for

Common NTFS Artifact Analysis exam traps

  • ▸Assuming $STANDARD_INFORMATION timestamps are authoritative; $FILE_NAME timestamps often preserve earlier creation times and can reveal timestomping.
  • ▸Treating $UsnJrnl as permanent; it is sparse and can be overwritten or deleted, so absence of records is not proof of no activity.
  • ▸Confusing $LogFile with $UsnJrnl; $LogFile is a circular transaction log for crash recovery, not a long-term user activity journal.

Practice set

NTFS Artifact Analysis questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following MFT attributes are most relevant for detecting timestomping activity?

Which THREE of the following are valid components of an NTFS MFT record?

Which NTFS attribute would an investigator examine to recover a deleted file's original name if the $MFT entry was partially overwritten?

Which THREE items are included in the $STANDARD_INFORMATION attribute?

An analyst is investigating a suspicious file and identifies that the filename is stored in the $FILE_NAME attribute but not in the $DATA attribute. What does this indicate regarding the file's state?

Which TWO of the following attributes in an NTFS MFT record are most critical for establishing the 'MACB' timeline of a file?

Based on the provided MFT exhibit, what forensic conclusion can be drawn regarding this file?

Exhibit

Refer to the exhibit.
Output: MFT Record 45892 - Flags: 0x01 (In Use) - $SI Modified: 2023-10-12 10:00:00 - $FN Modified: 2023-10-12 10:05:00

Which THREE of the following are valid NTFS system files that reside in the Master File Table?

Which THREE items are included in the $STANDARD_INFORMATION ($SI) attribute of an MFT record?

Based on the MFT exhibit provided, what is the status of this file?

Exhibit

Refer to the exhibit.
Output: MFT Record Flags: 0x00 - $SI Modified: 2023-01-01 10:00:00 - $DATA Attribute: None

A compromised Windows 10 workstation was imaged after an intruder deleted several files. You are examining the NTFS $MFT for evidence of file deletion. Which two MFT record header fields indicate that an MFT entry is no longer in use and was previously allocated to a file? (Choose two.)

You are examining a Windows 10 workstation and find that a user's Documents folder contains a file named 'budget.xlsx' with an MFT entry that has a $STANDARD_INFORMATION attribute with creation time 2023-08-10 09:15:00 and a $FILE_NAME attribute with creation time 2023-07-01 14:20:00. The $STANDARD_INFORMATION timestamps are all within a few seconds of each other, while the $FILE_NAME timestamps are from a month earlier. What is the most likely explanation for this discrepancy?

A forensic analyst is examining an NTFS volume and discovers that several MFT entries contain a $FILE_NAME attribute with a namespace value of 2 (POSIX). The analyst also notes that the corresponding $STANDARD_INFORMATION attribute shows a creation timestamp that is later than the modification timestamp. What is the most likely explanation for this discrepancy?

During an investigation of a compromised Windows server, an analyst finds that a suspicious executable's $STANDARD_INFORMATION timestamps show a creation time earlier than the volume's format date, while the $FILE_NAME timestamps appear consistent with recent activity. The analyst wants to determine whether the timestamps were manipulated using a known timestomping technique. Which NTFS artifact provides the most reliable evidence of timestomping in this scenario?

During a forensic examination of an NTFS volume, an analyst observes that a file's $STANDARD_INFORMATION timestamps show a Modified time of 2024-03-10 14:22:00, while the $FILE_NAME timestamps show a Modified time of 2024-03-08 09:15:00. The file is not a system file and has no apparent reason for the discrepancy. What is the most likely explanation for this difference?

An analyst is examining a Windows system and finds that a file named 'confidential.docx' has an MFT entry with a $STANDARD_INFORMATION attribute that includes a security ID. The analyst wants to determine which user account last accessed the file. Which NTFS artifact should the analyst examine to map the security ID to a user account?

During an investigation of a compromised Windows server, an analyst extracts an MFT record and observes that the $DATA attribute is non-resident and the $ATTRIBUTE_LIST attribute is present. The analyst also notes that the MFT record contains a $BITMAP attribute. Which statement best describes the forensic implication of these attributes appearing together in a single MFT entry?

A forensic analyst is examining an NTFS volume and wants to determine the original path of a file that has been moved to a different directory on the same volume. Which artifact provides the most reliable information about the file's original location?

During an investigation, an analyst discovers that a file's $STANDARD_INFORMATION attribute has a timestamp with a value that is not a valid NTFS timestamp (e.g., year 1601). What is the most likely cause of this anomaly?

An investigator is analyzing a Windows system and notices that a file's $STANDARD_INFORMATION timestamps show a creation date of 2020, while the $FILE_NAME timestamps show a creation date of 2023. The file's content appears to be from 2023. The investigator suspects timestomping. Which NTFS artifact should be examined to corroborate the true creation time by looking at when the file's MFT record was last modified?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused NTFS Artifact Analysis sessions

Start a NTFS Artifact Analysis only practice session

Every question in these sessions is drawn from the NTFS Artifact Analysis domain — nothing else.

Related practice questions

Related GCFA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCFA exam test about NTFS Artifact Analysis?
Be able to map a rename or deletion to the correct NTFS artifact and justify it with reason codes and timestamps. The single most important thing: know when to trust $UsnJrnl versus $LogFile versus $MFT metadata, and never rely on one timestamp alone.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just NTFS Artifact Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the NTFS Artifact Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCFA topics?
Use the topic links above to move to related areas, or go back to the GCFA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCFA exam covers. They are not copied from any real exam or dump site.