Courseiva
NTFS Artifact Analysis →easyMultiple Choice

GCFA NTFS Artifact Analysis Practice Question

Which NTFS metadata file serves as the index for all files and directories on the volume?

⚠ Common exam trap

Candidates often confuse the Master File Table ($MFT) with individual file records or system logs like $LogFile, failing to recognize that the $MFT itself is the root database indexing every file and directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$MFT

The Master File Table (MFT) is the central database of an NTFS volume. Every file and directory on the disk has at least one entry in the MFT. Understanding the MFT is the foundation of NTFS forensics, as it contains all the metadata necessary to identify file properties, permissions, and data locations, which are essential for rebuilding the state of the filesystem during an investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    $MFT

    Why this is correct

    The $MFT file is the primary repository for all file metadata. It stores the file name, size, permissions, and data location for every object on the volume. Without the $MFT, the operating system would be unable to locate or manage files, and forensic analysis would be severely hindered.

  • ✗

    $LogFile

    Why it's wrong here

    The $LogFile is an internal NTFS metadata file used for transaction logging and volume recovery. While useful for reconstructing recent filesystem actions, it is not the primary index or database of file metadata for the volume, and it does not store permanent records of file properties.

  • ✗

    $Boot

    Why it's wrong here

    The $Boot file contains the boot sector and the BIOS Parameter Block, which are necessary to start the operating system or mount the volume. It does not contain the file index or individual file metadata, making it irrelevant for tracking file system objects or user-created content.

  • ✗

    $Volume

    Why it's wrong here

    The $Volume file stores information about the volume itself, such as the volume name and version. It does not serve as an index for the files or directories stored on the disk, and it lacks the structural complexity required to manage user file data and attributes.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.