GCFA NTFS Artifact Analysis Practice Question
What is the primary advantage of the $UsnJrnl over the $LogFile for long-term forensic analysis?
⚠ Common exam trap
Candidates often confuse the $UsnJrnl with the $LogFile, assuming both serve the same short-term recovery purpose rather than recognizing the UsnJrnl's long-term persistence advantage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It has a much longer retention period.
The $UsnJrnl (Update Sequence Number Journal) is designed to track changes to files and directories over a long period. Unlike the $LogFile, which is a circular, short-term buffer for atomicity and recovery, the $UsnJrnl maintains a more persistent record of file activity. This makes it an invaluable source of historical metadata for investigators tracking how files were modified, created, or deleted over weeks or months.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It stores full file content for every transaction.
Why it's wrong here
The journal tracks changes to file metadata and flags; it does not store the file contents themselves. Saving full file data for every transaction would be prohibitively expensive in terms of storage and performance, so the journal focuses strictly on file actions like creation, deletion, and renaming.
- ✓
It has a much longer retention period.
Why this is correct
The $UsnJrnl is designed to track volume changes for administrative purposes, leading to a much larger storage capacity compared to the circular, high-frequency $LogFile. This allows analysts to view long-term trends and historical file operations, which is crucial for reconstructive analysis during an incident response engagement.
- ✗
It is not volatile and survives power loss.
Why it's wrong here
Both the $LogFile and $UsnJrnl are stored on disk and persist through power cycles. The distinction is not volatility, but the purpose and the size of the buffer; the $LogFile is optimized for crash recovery, while the $UsnJrnl is optimized for activity tracking and file system change notification.
- ✗
It contains the actual NTFS security descriptors.
Why it's wrong here
Security descriptors are stored in the $Secure file, not the $UsnJrnl. The journal is concerned with changes to file properties and volume state, not the authorization and access control logic that governs which users are permitted to read, write, or execute files on the NTFS volume.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.