Courseiva

GCFA Practice Question: Introduction to File System Timeline Forensics

Why should a forensic analyst avoid using the 'Last Accessed' time as the primary indicator for a file's usage?

⚠ Common exam trap

Candidates often assume that 'Last Accessed' timestamps reliably indicate when a user opened a file, overlooking frequent background system updates and the 'noatime' filesystem setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It is unreliable due to frequent updates by system services

The 'Last Accessed' timestamp is notoriously unreliable in forensic analysis because it is frequently updated by non-human system activity, such as antivirus scans or indexing services. Furthermore, many systems have the 'noatime' option enabled, which stops the OS from updating this field entirely. Because of this noise and potential for total absence, relying on this value for evidence of user activity is inherently dangerous and prone to producing false positives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It is only updated if the file is moved to a different folder

    Why it's wrong here

    Moving a file does not inherently trigger an access update in the same way reading it does. If it were only updated on moves, it would be a very poor indicator of file 'access'. In reality, it updates on read operations, which happens far more frequently, including by automated system tasks.

  • ✓

    It is unreliable due to frequent updates by system services

    Why this is correct

    Access times are updated by nearly any process that reads a file, including security software, search indexers, and background tasks. This makes it impossible to distinguish between a malicious user accessing a document and a background service performing a routine scan, rendering the timestamp unreliable for proving intentional user interaction.

  • ✗

    It is the most easily forged timestamp in the MFT

    Why it's wrong here

    While it can be forged, it is not uniquely 'the most' easily forged compared to other attributes like the modification time. The primary forensic issue is the volume of benign updates, not the ease of forgery. Forgery is a secondary concern compared to the lack of signal-to-noise ratio in this field.

  • ✗

    It only exists on FAT32 file systems

    Why it's wrong here

    Access time is a standard feature in NTFS as well as many Unix-based file systems like ext4. It is not limited to FAT32. The problem is not its existence, but the way modern operating systems manage its update frequency to save disk I/O, which makes the data inconsistent for forensic analysis.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.