GCFA Practice Question: Introduction to File System Timeline Forensics
What is the primary function of the $LogFile in NTFS when reconstructing a timeline?
⚠ Common exam trap
Candidates often mistake the $LogFile for a user activity log, failing to realize it is a low-level file system integrity mechanism that tracks metadata transactions, not user actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To record metadata transactions for file system integrity
The $LogFile is a circular buffer that records metadata transactions for the file system. It is invaluable for forensic analysts because it captures recent changes to the file system, including those that might not yet be committed to the MFT. By parsing the $LogFile, investigators can recover evidence of file creations, deletions, or renames that occurred shortly before an incident, providing a granular view of recent activity that might otherwise be lost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To store the actual file content data for quick retrieval
Why it's wrong here
The $LogFile is strictly for metadata transaction logging, not for storing the file content itself. File data is stored in clusters, and the log only tracks the operations related to metadata, such as updating MFT entries, ensuring the file system remains consistent even in the event of a system crash.
- ✗
To track all user-level file access and modification events
Why it's wrong here
The $LogFile tracks metadata transactions, which are internal file system operations. It does not record the user identity or the application that initiated the file access. Relying on it for user activity tracking is incorrect, as it serves the purpose of file system integrity rather than user-level activity auditing.
- ✓
To record metadata transactions for file system integrity
Why this is correct
The $LogFile is an essential component for NTFS transaction integrity. For a forensic investigator, it provides a chronologically ordered record of metadata changes. This allows for the reconstruction of recent events, enabling the identification of file system activity even if the standard MFT record has been updated or overwritten.
- ✗
To store backup copies of the Master File Table
Why it's wrong here
The $MFTMirr acts as a backup for the first few records of the MFT, not the $LogFile. The $LogFile is a dynamic, rotating transaction log, not a static backup, and it serves a completely different purpose within the NTFS architecture, specifically focused on consistency and crash recovery, not redundancy.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.