Courseiva

GCFA · topic practice

Windows Artifact Analysis practice questions

This domain covers forensic examination of NTFS metadata, registry-backed execution artifacts, and shell item databases on Windows hosts. GCFA tests whether you can interpret $MFT records, $STANDARD_INFORMATION versus $FILE_NAME timestamps, ShimCache/AmCache entries, UserAssist, and Jump Lists to reconstruct file creation, execution, and user activity from an acquired image.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Windows Artifact Analysis

What the exam tests

What to know about Windows Artifact Analysis

Be able to locate and interpret NTFS metadata, registry execution artifacts, and Jump Lists on a Windows image. The most important thing is distinguishing evidence of file presence from evidence of actual execution, and knowing which timestamps and artifacts can be trusted.

Interpreting $MFT record attributes, resident vs non-resident data, and $STANDARD_INFORMATION versus $FILE_NAME timestamps

Using ShimCache (AppCompatCache) and AmCache to infer executable presence versus confirmed execution

Parsing Jump Lists in AutomaticDestinations and CustomDestinations, including .automaticDestinations-ms OLE structure

Examining NTFS attributes such as hidden, system, and alternate data streams used to conceal files

Watch out for

Common Windows Artifact Analysis exam traps

  • ▸Treating a ShimCache entry as proof of execution; it only shows the file was seen by the system, not necessarily run.
  • ▸Assuming $STANDARD_INFORMATION timestamps are reliable; they are easily modified, unlike $FILE_NAME timestamps.
  • ▸Confusing Jump List folders or extensions, such as mixing AutomaticDestinations with CustomDestinations or wrong file suffixes.

Practice set

Windows Artifact Analysis questions

20 questions · select your answer, then reveal the explanation

An analyst discovers a suspicious executable in a user's AppData folder. Which Windows artifact should be examined first to determine if the file was executed via a specific user action or a scheduled task?

Which TWO of the following artifacts are most effective for identifying file system activity that occurred immediately before a system shutdown or sudden crash?

Refer to the exhibit. Based on the USN Journal output, what can the analyst conclude about the file 'secret_data.docx'?

Exhibit

C:\> fsutil usn readjournal C:\ /N
... 
File Name: secret_data.docx 
Reason: DataExtend, FileCreate, DataOverwrite, Close
Time: 2023-10-12 14:22:05

An analyst is investigating a compromised system and finds that the 'LastWrite' time of a specific registry key has been modified to match the surrounding keys. Which artifact should be checked to detect this timestomping attempt?

Which THREE pieces of information can be extracted from a parsed Windows 'Jump List' artifact?

Question 6mediummultiple choice
Read the full VPN explanation →

An analyst is investigating an unauthorized remote connection. Which artifact, located in the SYSTEM hive, provides evidence of network interface configuration changes that might indicate an attacker-controlled VPN or bridge?

Refer to the exhibit. An attacker modified the SpecialPollInterval value. What is the primary forensic implication of this change on a compromised system?

Exhibit

C:\Windows\System32\config\system
ControlSet001\Services\W32Time\TimeProviders\NtpClient
SpecialPollInterval: 3600

Which THREE artifacts are essential for identifying the presence and execution of 'Living off the Land' (LotL) binaries like PowerShell or WMI on a Windows host?

Refer to the exhibit. What is the significance of the 'LastWrite' time for this specific registry key?

Exhibit

C:\Windows\System32\config\SYSTEM
ControlSet001\Enum\USBSTOR\Disk&Ven_SanDisk&Prod_Cruzer_Glide
LastWrite Time: 2023-09-15 09:12:33

When reviewing 'ShimCache' (AppCompatCache), what does an entry with an empty 'Last Modified' time suggest to an investigator?

Which Windows artifact should an analyst investigate to identify the specific time a user last modified a local folder's view settings?

Which TWO of the following artifacts are most reliable for determining user-initiated file execution on a Windows 10 system?

Which THREE of the following items are commonly found within the Windows Prefetch file structure?

What is the primary forensic value of the Amcache.hve hive when investigating software installation on Windows 10?

Which THREE of the following items can typically be extracted from a LNK file during a forensic investigation?

An analyst is investigating a Windows 10 system where an attacker used PowerShell to download and execute a malicious script. The analyst wants to determine the PowerShell command-line arguments and script block content that were executed. Which TWO artifacts should the analyst examine to recover this information? (Choose two.)

An analyst is examining a Windows 10 workstation that is suspected of being used to exfiltrate data via a user-installed cloud-sync client. The analyst wants to correlate the exact times when files were added to a synced folder with network activity. Which Windows artifact should the analyst examine first to obtain the most direct record of individual file operations performed by that application?

An analyst is examining a Windows 10 system for evidence of a file that was recently deleted. The analyst suspects the file was removed using a command-line tool. Which artifact should be examined to determine the original path and deletion time of the file, assuming the file was deleted from an NTFS volume?

An analyst is examining a Windows 10 system suspected of being compromised. The analyst finds that the file `C:\Windows\System32\winevt\Logs\Security.evtx` has been deleted. A quick check of the volume shadow copies shows no recent copies. Which artifact should the analyst examine next to determine if the Security event log was cleared, and to recover potentially relevant event records?

An analyst is examining a Windows 10 system and wants to determine which user account was used to run a specific program that left a prefetch file. The prefetch file is named NOTEPAD.EXE-1A2B3C4D.pf. Which artifact should the analyst examine to correlate the prefetch execution with a user account?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Windows Artifact Analysis sessions

Start a Windows Artifact Analysis only practice session

Every question in these sessions is drawn from the Windows Artifact Analysis domain — nothing else.

Related practice questions

Related GCFA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCFA exam test about Windows Artifact Analysis?
Be able to locate and interpret NTFS metadata, registry execution artifacts, and Jump Lists on a Windows image. The most important thing is distinguishing evidence of file presence from evidence of actual execution, and knowing which timestamps and artifacts can be trusted.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Windows Artifact Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the Windows Artifact Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCFA topics?
Use the topic links above to move to related areas, or go back to the GCFA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCFA exam covers. They are not copied from any real exam or dump site.