GCFA NTFS Artifact Analysis Practice Question
Which NTFS metadata attribute is responsible for storing Security Descriptors (ACLs)?
⚠ Common exam trap
Candidates often guess standard data attributes like $DATA or file name attributes instead of looking specifically for security and access control structures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$SECURITY_DESCRIPTOR
The $SECURITY_DESCRIPTOR attribute contains the Access Control List (ACL) information for a file, which determines which users or groups can access it. Forensic analysts frequently examine this to identify if permissions have been modified to allow unauthorized access or if a sensitive file has had its permissions altered to hide it from standard administrative users on the system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
$FILE_NAME
Why it's wrong here
$FILE_NAME is for naming and basic timestamps. It does not contain any permission or security information. Confusing this with the security attribute would lead to a failure in identifying how a file's access is governed or whether it has been locked to prevent forensic examination.
- ✓
$SECURITY_DESCRIPTOR
Why this is correct
The $SECURITY_DESCRIPTOR attribute is specifically dedicated to storing the ACLs for a file. It defines the owner, the group, and the permissions granted to various users, which is essential for understanding the access control landscape of the system during a forensic investigation into unauthorized activity.
- ✗
$ATTRIBUTE_LIST
Why it's wrong here
$ATTRIBUTE_LIST is a structural attribute used for managing files with many attributes. It does not store actual security data. Relying on it for permission analysis would be incorrect, as it only points to where other attributes are stored, not to the actual access control logic.
- ✗
$DATA
Why it's wrong here
$DATA stores the payload content. It is entirely unrelated to the security descriptors or access control lists that regulate who is allowed to view, read, or write to that payload. Searching here for ACL information would yield no results relevant to file permissions.
Visual reference
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.