Courseiva
NTFS Artifact Analysis →hardMultiple Select

GCFA NTFS Artifact Analysis Practice Question

You are analyzing an NTFS volume and need to determine the original path and name of a file that has been moved to a different directory. The file's MFT entry contains multiple $FILE_NAME attributes. Which two of the following statements about $FILE_NAME attributes are correct? (Choose two.)

⚠ Common exam trap

The trap here is assuming that $FILE_NAME attributes preserve historical paths or that they are updated on content modification, when they actually reflect current hard links and static timestamps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The $FILE_NAME attribute includes a namespace field that indicates whether the name is in the POSIX, Win32, or DOS namespace.

$FILE_NAME attributes represent hard links; each link has a parent directory reference pointing to the directory containing the link. The namespace field indicates the naming convention used. These attributes are always resident and their timestamps update on rename or move, not content modification. Multiple $FILE_NAME attributes therefore indicate multiple hard links, and their parent references help reconstruct directory structure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The $FILE_NAME attribute stores the file's original path when the file was moved, and the parent directory reference points to the original directory.

    Why it's wrong here

    When a file is moved within the same volume, NTFS updates the parent directory reference in the $FILE_NAME attribute to the new directory. The old path is not preserved. The $FILE_NAME attribute reflects the current location, not the original. This option incorrectly suggests that the original path is retained.

  • ✓

    The $FILE_NAME attribute includes a namespace field that indicates whether the name is in the POSIX, Win32, or DOS namespace.

    Why this is correct

    The $FILE_NAME attribute has a namespace field that specifies the naming convention: POSIX (0), Win32 (1), DOS (2), or Win32 & DOS (3). This field helps determine the format of the filename, such as whether it is a short 8.3 name or a long name. It is a standard part of the attribute.

  • ✓

    Each $FILE_NAME attribute corresponds to a hard link to the file, and the parent directory reference points to the directory containing that link.

    Why this is correct

    In NTFS, a file can have multiple hard links, and each hard link is represented by a $FILE_NAME attribute. The parent directory reference in each $FILE_NAME points to the MFT entry of the directory that contains that link. Thus, multiple $FILE_NAME attributes indicate multiple hard links, and their parent references reveal the directories.

  • ✗

    The $FILE_NAME attribute is updated whenever the file's content is modified, reflecting the last modification time.

    Why it's wrong here

    The $FILE_NAME attribute's timestamps are updated on file creation, rename, or move, but not on content modification. Content modification updates the $STANDARD_INFORMATION timestamps. The $FILE_NAME timestamps are more static, which is why discrepancies between the two sets can indicate timestomping.

  • ✗

    The $FILE_NAME attribute can be resident or non-resident depending on the length of the filename.

    Why it's wrong here

    The $FILE_NAME attribute is always resident in the MFT entry because filenames are limited to 255 characters, which fits within the MFT entry's resident attribute space. It is never non-resident. This option is incorrect because it suggests non-residency is possible.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.