Courseiva
Windows Forensics →hardMultiple Choice

GSEC Windows Forensics Practice Question

A forensic examiner is reviewing an NTFS volume from a Windows 11 laptop. The user claims a sensitive spreadsheet was only opened and never modified or renamed. The examiner notes that the $STANDARD_INFORMATION timestamps for the file are all recent, but the $FILE_NAME timestamps are from several months earlier. Which explanation best accounts for this discrepancy?

⚠ Common exam trap

The trap here is treating the two NTFS timestamp sets as always identical and therefore dismissing the discrepancy instead of recognizing it as a timestomping or API-behavior indicator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file was accessed by a program that updated the $STANDARD_INFORMATION timestamps, and this behavior is a known anti-forensic technique or normal filesystem behavior depending on the API used.

NTFS maintains parallel timestamps in $STANDARD_INFORMATION and $FILE_NAME. Many APIs and many anti-forensic tools update only the $STANDARD_INFORMATION set, leaving $FILE_NAME untouched. A recent $STANDARD_INFORMATION paired with an older $FILE_NAME is a classic timestomping indicator and directly explains the discrepancy the examiner observed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows 11 disables $FILE_NAME timestamp updates by default for user documents, so the older values simply reflect the file's creation date.

    Why it's wrong here

    Windows does not disable $FILE_NAME timestamp updates for user documents; NTFS continues to maintain those timestamps on rename and related operations. The $FILE_NAME attribute is part of the directory index entry and is actively managed. Default OS behavior does not produce a months-old $FILE_NAME with a recent $STANDARD_INFORMATION, so this explanation is incorrect.

  • ✓

    The file was accessed by a program that updated the $STANDARD_INFORMATION timestamps, and this behavior is a known anti-forensic technique or normal filesystem behavior depending on the API used.

    Why this is correct

    NTFS stores two sets of timestamps: $STANDARD_INFORMATION, which many APIs update, and $FILE_NAME, which is typically updated only on rename or certain metadata changes. Tools and some APIs can modify $STANDARD_INFORMATION times without touching $FILE_NAME, producing exactly this discrepancy. It is a well-documented artifact and a common timestomping indicator, so this explanation fits the evidence best.

  • ✗

    The $FILE_NAME timestamps record when the file was last backed up, while the $STANDARD_INFORMATION timestamps record live activity, so they legitimately differ after any backup.

    Why it's wrong here

    The $FILE_NAME attribute timestamps are not a backup log; they are maintained by NTFS and updated on rename and certain metadata operations. Backup software does not write into $FILE_NAME to record backup times. This misconception would cause an examiner to dismiss a real timestomping indicator, so it is not a valid explanation for the observed timestamp divergence.

  • ✗

    The file was copied onto the volume from a remote share, which rewrote the $STANDARD_INFORMATION times while preserving the $FILE_NAME times from the source.

    Why it's wrong here

    Copying a file to a new volume generally creates a new file with fresh timestamps in both attribute sets; the $FILE_NAME times are not carried over from the source file's MFT record. A remote copy would not selectively update one timestamp set while preserving the other from months earlier. This does not match the observed pattern of a recent $STANDARD_INFORMATION and an older $FILE_NAME.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.