GCFA Windows Artifact Analysis Practice Question
What is the primary function of the ShellBags artifact in a Windows forensic investigation?
⚠ Common exam trap
Candidates often assume ShellBags only track files that currently exist, failing to realize the artifact persists even after the target folders or external drives have been removed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To demonstrate that a user navigated to a specific folder.
ShellBags are registry entries that store folder view preferences, such as window size, icon position, and folder sorting. For forensics, they are incredibly useful for proving that a user navigated to a specific directory in Windows Explorer. This is critical for demonstrating user intent, as it shows which folders were browsed, even if those folders were later deleted or were located on removable media that is no longer connected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To track the history of web browser searches.
Why it's wrong here
ShellBags track local file explorer activity, not web browsing. Confusing these two means an analyst will focus on the registry instead of browser history files (like History or Places.sqlite), leading to a complete failure to document the attacker's web-based research and activities, which is a major investigative gap.
- ✗
To log file deletion events in the Recycle Bin.
Why it's wrong here
Recycle Bin activity is tracked in the $I and $R files within the $Recycle.Bin directory. ShellBags are entirely unrelated to the Recycle Bin. Misattributing deletion activity to ShellBags will lead to a false narrative about what files were deleted or when the activity occurred during the incident timeline.
- ✓
To demonstrate that a user navigated to a specific folder.
Why this is correct
ShellBags registry keys are updated when a user opens a folder. Because these keys persist even after folders are deleted, they are excellent evidence for showing the user was present in a directory. This helps confirm user knowledge of specific files or directories during a forensic examination.
- ✗
To record the last time a system was rebooted.
Why it's wrong here
Reboot timestamps are recorded in the System event logs (Event ID 6005/6006) and the registry's shutdown time keys. ShellBags do not contain system uptime or reboot data. Relying on them for system timelines is inaccurate and will result in a flawed incident timeline, potentially missing critical reboot-related events.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.