GCFA File System Timeline Artifact Analysis Practice Question
Which TWO of the following actions are considered 'anti-forensic' techniques that directly impact file system timeline analysis?
⚠ Common exam trap
Candidates often confuse general system maintenance tasks with anti-forensic techniques, failing to identify that log clearing and timestomping are specifically intended to obstruct the reconstruction of a timeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Timestomping
Attackers utilize anti-forensic techniques to break the chain of evidence. Timestomping specifically invalidates the reliability of file metadata, while log clearing removes the context required for correlation. Both techniques force analysts to move deeper into secondary artifacts like the USN Journal or volume shadow copies, significantly increasing the time and complexity of an investigation while testing the analyst's ability to cross-reference multiple data sources for evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Updating system drivers
Why it's wrong here
Updating system drivers is a standard administrative task. While it changes file timestamps, it is not considered an 'anti-forensic' technique. It is a predictable, documented activity that is part of normal system maintenance and does not involve the malicious intent to hide evidence or deceive investigators during a timeline analysis.
- ✓
Timestomping
Why this is correct
Timestomping is the intentional modification of file metadata to mislead investigators. By altering the SI attributes, an attacker hides the true age of a malicious file, making it appear as a legitimate system file or part of a different time window, which is a direct attack on forensic timeline integrity.
- ✓
Log clearing
Why this is correct
Clearing event logs is a classic anti-forensic measure taken to destroy the audit trail. Without log data, an investigator loses the capability to correlate file system events with user activity, preventing the reconstruction of an accurate narrative regarding how, when, and by whom a file was created or modified.
- ✗
Using a web browser
Why it's wrong here
Using a web browser is a standard user activity. While it creates history files and temporary artifacts, these are the expected byproducts of normal usage. They are not anti-forensic in nature, as they provide valuable evidence rather than destroying it, and are essential for reconstructing user-level activity in an investigation.
- ✗
Renaming a file
Why it's wrong here
Renaming a file is a routine file system operation. While it might be used by an attacker to hide a malicious file in plain sight, the act of renaming does not fundamentally destroy evidence or provide a technical hurdle to forensic timeline reconstruction, unlike true anti-forensic measures like log deletion.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.