GCFA NTFS Artifact Analysis Practice Question
What is the significance of the $LogFile in NTFS when performing an investigation on a system that experienced a sudden power loss?
⚠ Common exam trap
Candidates often confuse the $LogFile with the Event Logs or the USN Journal, mistakenly assuming it contains application-level activity logs rather than low-level filesystem transaction metadata used for crash recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It records transaction metadata for crash recovery.
The $LogFile is a circular buffer that records metadata operations before they are finalized. When a system crashes or loses power, the NTFS driver uses the $LogFile upon reboot to replay or undo incomplete transactions, ensuring volume consistency. For investigators, it provides a window into the state of the filesystem immediately before the crash, potentially recovering records of files modified just before the power failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It stores user credentials for encrypted sessions.
Why it's wrong here
The $LogFile is an internal NTFS metadata structure and does not store credentials or session-specific data. Security-related data, such as login credentials, are handled by the LSASS process and stored in the Security Accounts Manager (SAM) or memory, not the filesystem metadata log files.
- ✓
It records transaction metadata for crash recovery.
Why this is correct
The $LogFile ensures that NTFS can recover from crashes by logging metadata transactions. Investigators can parse this to see recent file system changes that were in progress. This makes it a high-value artifact for reconstructing activity that occurred immediately preceding a system crash or intentional shutdown.
- ✗
It keeps a copy of all deleted file contents.
Why it's wrong here
The $LogFile is a transaction log for metadata, not a backup repository for deleted file content. It records operations, not the deleted file payloads. While it might show that a file was deleted, it will not contain the original data of that file, which remains in the unallocated clusters.
- ✗
It is used by BitLocker to verify volume integrity.
Why it's wrong here
BitLocker uses volume-level integrity headers and key protectors, not the $LogFile. The $LogFile is a native NTFS function for filesystem consistency and is completely independent of BitLocker volume encryption mechanisms, which operate at a layer below the NTFS file system parsing level.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.