Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

Why might an analyst prefer using 'Super-Timeline' creation tools, such as log2timeline, over manual collection of file system timestamps?

⚠ Common exam trap

Candidates mistakenly believe that manual timestamp collection provides the same contextual depth as super-timelines, missing the crucial correlation with registry and event logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

They provide a comprehensive view by integrating metadata from multiple sources.

Super-timelines aggregate data from diverse sources including file systems, event logs, registry hives, and application-specific artifacts into a single chronological view. Manual timestamp collection is limited to file system metadata, which often fails to capture the 'why' behind an event. By aggregating disparate data, analysts can correlate file changes with system events, providing a much richer, holistic context that is necessary to solve complex, multi-stage security incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    They automatically decrypt all files for easier analysis.

    Why it's wrong here

    Super-timeline tools do not possess the capability to decrypt files without the appropriate keys. Their primary purpose is parsing and aggregation, not cryptanalysis. Relying on this assumption could lead an analyst to believe they have access to content they do not actually have, potentially wasting valuable investigation time.

  • ✓

    They provide a comprehensive view by integrating metadata from multiple sources.

    Why this is correct

    By combining registry, log, and file system artifacts, these tools provide a complete narrative. This integration allows the analyst to see the causal relationship between events, such as a process execution event in a log file followed by a file modification in the NTFS MFT, which is crucial for reconstruction.

  • ✗

    They eliminate the need to preserve original forensic images.

    Why it's wrong here

    Forensic integrity requires the preservation of the original image. Super-timeline tools are merely a way to process that image; they are not a substitute for the image itself. Deleting the original evidence because an analyst has a processed timeline is a fundamental violation of forensic procedures and chain of custody.

  • ✗

    They ensure all files are permanently deleted from the disk.

    Why it's wrong here

    These tools are for analysis and visualization, not for data destruction. Claiming they delete files is completely inaccurate. Using such tools to 'clean up' a system would be an act of spoliation, destroying the evidence that the analyst is supposed to be examining, which is a major ethical and procedural failure.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.