Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

Which of the following describes the 'MAC' in MACB times during timeline analysis?

⚠ Common exam trap

Candidates occasionally confuse 'Change' with 'Creation,' thinking 'C' stands for creation. In NTFS, 'C' stands for MFT entry modification (Change), while 'Birth' represents the file creation time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modification, Access, Change, and Birth.

MACB refers to the four primary timestamps: Modification, Access, Change, and Birth (Creation). These are the fundamental metadata points recorded by file systems. Understanding these timestamps is the core of timeline forensics, as they allow analysts to reconstruct the sequence of events. Each timestamp provides a different perspective on how a file was interacted with, enabling the investigator to distinguish between reading, editing, and creating files on the disk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Memory, Application, Cache, and Buffer.

    Why it's wrong here

    These are concepts related to system performance and volatile data storage, not file system metadata. Confusing these with MACB timestamps would lead an analyst to look in the wrong places for evidence, missing the chronological indicators stored within the file system's metadata structures that are necessary for building a forensic timeline.

  • ✓

    Modification, Access, Change, and Birth.

    Why this is correct

    Modification tracks content changes, Access tracks reading, Change tracks metadata updates, and Birth tracks file creation. These four points are essential for building a comprehensive view of file activity. By analyzing these, an investigator can determine if an attacker simply viewed a file or if they modified its contents.

  • ✗

    Main, Auxiliary, Configuration, and Backup.

    Why it's wrong here

    These terms refer to system architecture or backup strategies, not file system attributes. A forensic analyst must strictly distinguish between these hardware or software components and the actual metadata timestamps stored by the file system. Relying on this incorrect definition would result in a complete failure to analyze file history.

  • ✗

    Master, Allocation, Cluster, and Bit-map.

    Why it's wrong here

    These are components of the file system structure itself, such as the Master File Table or the allocation bitmap. While these are important for deep-dive analysis, they are not the timestamps required for a MACB timeline. Confusing these will prevent the analyst from effectively reconstructing the chronological sequence of events.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.