GCFA NTFS Artifact Analysis Practice Question
What is the primary purpose of the $LogFile in NTFS?
⚠ Common exam trap
Candidates often assume the $LogFile is intended for user activity tracking or auditing, failing to recognize its technical purpose as a filesystem consistency mechanism for crash recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To prevent filesystem corruption.
The $LogFile is essential for maintaining NTFS consistency. It records all metadata changes before they are committed, allowing the system to recover from crashes by rolling back or completing interrupted operations. While the $LogFile is circular and does not store user data, its entries can often reveal the order of operations, helping an investigator reconstruct the sequence of events leading up to a system compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To track user login history.
Why it's wrong here
The $LogFile tracks filesystem metadata transactions, not user-level authentication or login events. User activity is typically recorded in Windows Event Logs (such as Security.evtx), and using the $LogFile for tracking logins would be a fundamental misunderstanding of the Windows operating system's logging architecture.
- ✓
To prevent filesystem corruption.
Why this is correct
The $LogFile ensures atomic updates to metadata. By logging transactions before applying them, the NTFS driver can restore the volume to a consistent state following an unexpected power loss or system failure, which is the core requirement for modern, reliable file system operation.
- ✗
To store backup copies of files.
Why it's wrong here
The $LogFile is too small and volatile to be used for storing file backups. It is a temporary transaction log, not a storage repository. Attempting to recover files from the $LogFile would be impossible, as it contains only metadata operation records, not the original file content.
- ✗
To record all file access logs.
Why it's wrong here
The $LogFile does not log every 'read' or 'access' event. It logs 'metadata transactions' related to file system operations (like changing permissions or renaming files). Recording every single file access would create an unsustainable performance overhead and generate an unmanageable amount of log data.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.