Courseiva
NTFS Artifact Analysis →mediumMultiple Choice

GCFA NTFS Artifact Analysis Practice Question

Which NTFS metadata attribute is responsible for storing Security Descriptors (ACLs)?

⚠ Common exam trap

Candidates often guess standard data attributes like $DATA or file name attributes instead of looking specifically for security and access control structures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$SECURITY_DESCRIPTOR

The $SECURITY_DESCRIPTOR attribute contains the Access Control List (ACL) information for a file, which determines which users or groups can access it. Forensic analysts frequently examine this to identify if permissions have been modified to allow unauthorized access or if a sensitive file has had its permissions altered to hide it from standard administrative users on the system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    $FILE_NAME

    Why it's wrong here

    $FILE_NAME is for naming and basic timestamps. It does not contain any permission or security information. Confusing this with the security attribute would lead to a failure in identifying how a file's access is governed or whether it has been locked to prevent forensic examination.

  • ✓

    $SECURITY_DESCRIPTOR

    Why this is correct

    The $SECURITY_DESCRIPTOR attribute is specifically dedicated to storing the ACLs for a file. It defines the owner, the group, and the permissions granted to various users, which is essential for understanding the access control landscape of the system during a forensic investigation into unauthorized activity.

  • ✗

    $ATTRIBUTE_LIST

    Why it's wrong here

    $ATTRIBUTE_LIST is a structural attribute used for managing files with many attributes. It does not store actual security data. Relying on it for permission analysis would be incorrect, as it only points to where other attributes are stored, not to the actual access control logic.

  • ✗

    $DATA

    Why it's wrong here

    $DATA stores the payload content. It is entirely unrelated to the security descriptors or access control lists that regulate who is allowed to view, read, or write to that payload. Searching here for ACL information would yield no results relevant to file permissions.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.