Courseiva
Windows Artifact Analysis →mediumMultiple Choice

GCFA Windows Artifact Analysis Practice Question

When reviewing Jump Lists on a Windows system, which file extension is commonly associated with the 'AutomaticDestinations' folder?

⚠ Common exam trap

Candidates often assume all Jump List files share the same extension, failing to differentiate between the 'AutomaticDestinations' and 'CustomDestinations' naming conventions used by the operating system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

.automaticDestinations-ms

Jump Lists, located in the AutomaticDestinations and CustomDestinations folders, track recently accessed files and applications. The files are identified by an AppID, which is a hash of the application's path. These files often end with the .automaticDestinations-ms extension. They are vital for identifying files opened by users, providing insight into document access, media playback, and tool usage that may relate to intellectual property theft or evidence of work.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    .pf

    Why it's wrong here

    Files with the .pf extension are Prefetch files. Confusing Jump Lists with Prefetch files leads to incorrect parsing attempts. Jump Lists require different tools and focus on user activity and file access, whereas Prefetch files are focused on system performance and application execution, serving two entirely different forensic purposes.

  • ✓

    .automaticDestinations-ms

    Why this is correct

    The .automaticDestinations-ms extension is used for the files stored in the AutomaticDestinations folder. These files contain lists of recently accessed items for a specific application. Identifying these files allows an analyst to extract document names, folder paths, and timestamps related to the user's recent file interaction history.

  • ✗

    .log

    Why it's wrong here

    .log files are general text or binary logs used by various Windows components. They are not specific to Jump Lists. Assuming Jump Lists are simple .log files will lead an analyst to attempt text-based analysis, which is ineffective against the OLE compound file structure used by actual Jump List files.

  • ✗

    .lnk

    Why it's wrong here

    While Jump Lists contain LNK file structures, the actual files in the AutomaticDestinations folder have the -ms extension. If an analyst expects to find only .lnk files, they will fail to locate the repository that holds the collection of recently accessed files, ultimately missing critical user activity evidence.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.