Courseiva
NTFS Artifact Analysis →mediumMultiple Choice

GCFA NTFS Artifact Analysis Practice Question

What is the significance of the $LogFile in NTFS when performing an investigation on a system that experienced a sudden power loss?

⚠ Common exam trap

Candidates often confuse the $LogFile with the Event Logs or the USN Journal, mistakenly assuming it contains application-level activity logs rather than low-level filesystem transaction metadata used for crash recovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It records transaction metadata for crash recovery.

The $LogFile is a circular buffer that records metadata operations before they are finalized. When a system crashes or loses power, the NTFS driver uses the $LogFile upon reboot to replay or undo incomplete transactions, ensuring volume consistency. For investigators, it provides a window into the state of the filesystem immediately before the crash, potentially recovering records of files modified just before the power failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It stores user credentials for encrypted sessions.

    Why it's wrong here

    The $LogFile is an internal NTFS metadata structure and does not store credentials or session-specific data. Security-related data, such as login credentials, are handled by the LSASS process and stored in the Security Accounts Manager (SAM) or memory, not the filesystem metadata log files.

  • ✓

    It records transaction metadata for crash recovery.

    Why this is correct

    The $LogFile ensures that NTFS can recover from crashes by logging metadata transactions. Investigators can parse this to see recent file system changes that were in progress. This makes it a high-value artifact for reconstructing activity that occurred immediately preceding a system crash or intentional shutdown.

  • ✗

    It keeps a copy of all deleted file contents.

    Why it's wrong here

    The $LogFile is a transaction log for metadata, not a backup repository for deleted file content. It records operations, not the deleted file payloads. While it might show that a file was deleted, it will not contain the original data of that file, which remains in the unallocated clusters.

  • ✗

    It is used by BitLocker to verify volume integrity.

    Why it's wrong here

    BitLocker uses volume-level integrity headers and key protectors, not the $LogFile. The $LogFile is a native NTFS function for filesystem consistency and is completely independent of BitLocker volume encryption mechanisms, which operate at a layer below the NTFS file system parsing level.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.