GCFA Windows Artifact Analysis Practice Question
When reviewing Jump Lists on a Windows system, which file extension is commonly associated with the 'AutomaticDestinations' folder?
⚠ Common exam trap
Candidates often assume all Jump List files share the same extension, failing to differentiate between the 'AutomaticDestinations' and 'CustomDestinations' naming conventions used by the operating system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
.automaticDestinations-ms
Jump Lists, located in the AutomaticDestinations and CustomDestinations folders, track recently accessed files and applications. The files are identified by an AppID, which is a hash of the application's path. These files often end with the .automaticDestinations-ms extension. They are vital for identifying files opened by users, providing insight into document access, media playback, and tool usage that may relate to intellectual property theft or evidence of work.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
.pf
Why it's wrong here
Files with the .pf extension are Prefetch files. Confusing Jump Lists with Prefetch files leads to incorrect parsing attempts. Jump Lists require different tools and focus on user activity and file access, whereas Prefetch files are focused on system performance and application execution, serving two entirely different forensic purposes.
- ✓
.automaticDestinations-ms
Why this is correct
The .automaticDestinations-ms extension is used for the files stored in the AutomaticDestinations folder. These files contain lists of recently accessed items for a specific application. Identifying these files allows an analyst to extract document names, folder paths, and timestamps related to the user's recent file interaction history.
- ✗
.log
Why it's wrong here
.log files are general text or binary logs used by various Windows components. They are not specific to Jump Lists. Assuming Jump Lists are simple .log files will lead an analyst to attempt text-based analysis, which is ineffective against the OLE compound file structure used by actual Jump List files.
- ✗
.lnk
Why it's wrong here
While Jump Lists contain LNK file structures, the actual files in the AutomaticDestinations folder have the -ms extension. If an analyst expects to find only .lnk files, they will fail to locate the repository that holds the collection of recently accessed files, ultimately missing critical user activity evidence.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.