GCFA NTFS Artifact Analysis Practice Question
What is the primary function of the $ATTRIBUTE_LIST attribute in an MFT entry?
⚠ Common exam trap
Candidates often assume an MFT record is always self-contained, failing to account for the $ATTRIBUTE_LIST which allows files to span multiple MFT records when metadata is too large.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To reference attributes stored in other MFT records.
The $ATTRIBUTE_LIST attribute is used when an MFT record is too small to hold all of a file's attributes. By storing a list of references to other MFT records, NTFS allows a single file to span multiple records. This is a crucial concept for analysts because it means that critical evidence, such as timestamps or data runs, might be hidden in secondary MFT records outside the primary entry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To index directory contents.
Why it's wrong here
Directory indexing is handled by the $INDEX_ROOT and $INDEX_ALLOCATION attributes, not $ATTRIBUTE_LIST. These index attributes enable fast searching and sorting of files within a directory, whereas $ATTRIBUTE_LIST is purely for managing the storage of metadata for files with excessive attribute information attached.
- ✗
To store extended file permissions.
Why it's wrong here
Permissions are stored in the $SECURITY_DESCRIPTOR attribute. $ATTRIBUTE_LIST has no role in managing security or access control lists; its purpose is strictly structural, intended to provide a mechanism for files that exceed the storage capacity of a single 1024-byte MFT record on the volume.
- ✓
To reference attributes stored in other MFT records.
Why this is correct
When a file's attributes exceed the size of one MFT record, the $ATTRIBUTE_LIST attribute is created. It acts as a pointer map, listing the location and type of attributes held in additional MFT records, ensuring that the operating system can still access the complete metadata set for the file.
- ✗
To track file deletion history.
Why it's wrong here
NTFS does not maintain a formal 'deletion history' as a metadata attribute. While file metadata remains in unallocated MFT entries after deletion, no specific attribute exists to track when or how a file was deleted; that information must be inferred through analysis of the $LogFile or $UsnJrnl.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.