
GIAC Certified Forensic Analyst
Domain 3Objective 2
File System Timeline Artifact Analysis GCFA Practice Questions (Page 1)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
Questions 1–5
- 1
An analyst is reviewing a timeline and wants to identify all files that were modified during a specific 15-minute window. The timeline contains millions of entries. Which technique is most efficient for this task?
Select an answer first - 2
An analyst is investigating a malware infection. The file system timeline shows that a file 'svchost.exe' was created in the 'C:\Windows\System32' directory at 03:00:00 UTC. The Security event log shows a service installation event at 03:00:05 UTC. The file's $STANDARD_INFORMATION creation time is 03:00:00 UTC, and its modification time is 03:00:10 UTC. The analyst also finds that the file's digital signature is invalid. Which conclusion is best supported?
Select an answer first - 3
An analyst is building a timeline from a Windows 10 system image. The user's Documents folder contains a file that was created on Monday, but the $STANDARD_INFORMATION (SI) creation timestamp shows Sunday. The $FILE_NAME (FN) creation timestamp shows Monday. The analyst needs to determine which timestamp reflects the actual file creation for the investigation. What should the analyst do?
Select an answer first - 4
In NTFS, which metadata attribute contains the MAC times that are most commonly modified by the operating system when a file is accessed or changed?
Select an answer first - 5
An analyst is examining a timeline of file system activity from a compromised Linux server. The timeline contains thousands of entries, and the analyst needs to identify files that were modified during the suspected breach window (02:00–03:00 UTC). Which technique is most effective for isolating relevant entries?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.