GCFA File System Timeline Artifact Analysis Practice Question
What is the primary function of the $LogFile in an NTFS file system?
⚠ Common exam trap
Candidates often mistake the $LogFile for a user activity log, failing to realize its primary purpose is system recovery and consistency, not tracking user-level actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To support file system recovery and consistency.
The $LogFile is a circular buffer used to ensure file system consistency, particularly during system crashes. It records metadata transactions, allowing the system to roll back or finish operations that were interrupted. For forensic analysts, the $LogFile acts as a record of 'in-progress' operations that may not have been committed to the MFT yet, providing an essential look into very recent system activity that is otherwise invisible in standard MFT analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To store user authentication logs.
Why it's wrong here
The $LogFile is an internal file system structure for integrity and recovery. Authentication logs are stored in the Windows Security Event log (.evtx), not in the file system metadata structures. Confusing these two logs leads to incorrect forensic conclusions and a misunderstanding of how Windows maintains audit trails.
- ✓
To support file system recovery and consistency.
Why this is correct
The $LogFile is a journal of transactions used by NTFS to ensure that the file system remains in a consistent state if a crash occurs. It tracks changes to metadata before they are finalized in the MFT, making it a critical source for investigating recent, volatile file system activity.
- ✗
To track file access by unauthorized users.
Why it's wrong here
The $LogFile does not track user identity or access permissions. Its sole purpose is structural integrity of the file system. Relying on the $LogFile for user attribution or security auditing is incorrect, as it focuses on raw metadata transactions rather than the entities performing those actions.
- ✗
To store the contents of deleted files.
Why it's wrong here
Deleted file contents are not stored in the $LogFile. The $LogFile records the metadata transaction of the deletion, not the content of the file itself. Recovering deleted content requires carving for file signatures in unallocated space, as the journal does not preserve data payloads for forensic recovery.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.