GCFA Practice Question: Introduction to File System Timeline Forensics
Which of the following describes the 'MAC' in MACB times during timeline analysis?
⚠ Common exam trap
Candidates occasionally confuse 'Change' with 'Creation,' thinking 'C' stands for creation. In NTFS, 'C' stands for MFT entry modification (Change), while 'Birth' represents the file creation time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modification, Access, Change, and Birth.
MACB refers to the four primary timestamps: Modification, Access, Change, and Birth (Creation). These are the fundamental metadata points recorded by file systems. Understanding these timestamps is the core of timeline forensics, as they allow analysts to reconstruct the sequence of events. Each timestamp provides a different perspective on how a file was interacted with, enabling the investigator to distinguish between reading, editing, and creating files on the disk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Memory, Application, Cache, and Buffer.
Why it's wrong here
These are concepts related to system performance and volatile data storage, not file system metadata. Confusing these with MACB timestamps would lead an analyst to look in the wrong places for evidence, missing the chronological indicators stored within the file system's metadata structures that are necessary for building a forensic timeline.
- ✓
Modification, Access, Change, and Birth.
Why this is correct
Modification tracks content changes, Access tracks reading, Change tracks metadata updates, and Birth tracks file creation. These four points are essential for building a comprehensive view of file activity. By analyzing these, an investigator can determine if an attacker simply viewed a file or if they modified its contents.
- ✗
Main, Auxiliary, Configuration, and Backup.
Why it's wrong here
These terms refer to system architecture or backup strategies, not file system attributes. A forensic analyst must strictly distinguish between these hardware or software components and the actual metadata timestamps stored by the file system. Relying on this incorrect definition would result in a complete failure to analyze file history.
- ✗
Master, Allocation, Cluster, and Bit-map.
Why it's wrong here
These are components of the file system structure itself, such as the Master File Table or the allocation bitmap. While these are important for deep-dive analysis, they are not the timestamps required for a MACB timeline. Confusing these will prevent the analyst from effectively reconstructing the chronological sequence of events.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.