GCFA Practice Question: Identification of Malicious and Normal Activity
What is the primary forensic value of examining MFT (Master File Table) $Standard_Information vs $File_Name attributes?
⚠ Common exam trap
Candidates often assume that the MFT always reflects the true file creation time. They fail to realize that attackers frequently target the Standard Information attribute while neglecting the File Name attribute.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Discrepancies often reveal timestomping attempts by attackers.
The MFT contains two primary timestamps for each file: Standard Information (SI) and File Name (FN). Attackers often use 'timestomping' tools to modify the SI attributes to match legitimate files and hide their tracks. However, they frequently forget or are unable to modify the FN attributes, which are less accessible. Discrepancies between these timestamps are a definitive indicator of anti-forensic activity that analysts use to uncover hidden malicious file creation times.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SI attributes are updated by the OS, while FN attributes are static.
Why it's wrong here
Both attribute types are updated by the OS during file operations. The difference lies in the accessibility to user-mode tools. Timestomping specifically targets the SI attributes because they are commonly used by standard file system tools, while FN attributes remain unchanged, providing a record of the actual file creation time.
- ✓
Discrepancies often reveal timestomping attempts by attackers.
Why this is correct
Attackers frequently modify the SI attributes to make malicious files appear older or consistent with other system files. Because they often overlook the FN attributes, comparing the two reveals the manipulation. This discrepancy is a standard forensic indicator used to identify hidden files that were created or modified maliciously.
- ✗
FN attributes are the only way to recover deleted files.
Why it's wrong here
Deleted files are recovered by parsing the MFT records and data runs, not by comparing attribute timestamps. While FN attributes provide metadata, they are not the mechanism for data recovery. Confusing these concepts leads to incorrect forensic methodologies that fail to address the actual challenge of file recovery.
- ✗
SI attributes are required for NTFS file permissions.
Why it's wrong here
NTFS file permissions are handled by the Security Descriptor, not the Standard Information attribute. The SI attribute is strictly for file metadata such as timestamps. The existence of permission structures is independent of the timing metadata, making this explanation technically incorrect regarding how the Windows file system manages security.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.