Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 3Objective 2

File System Timeline Artifact Analysis GCFA Practice Questions (Page 1)

Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
5concepts

Questions 1–5

  1. 1application · medium

    An analyst is reviewing a timeline and wants to identify all files that were modified during a specific 15-minute window. The timeline contains millions of entries. Which technique is most efficient for this task?

    Select an answer first
  2. 2expert · hard

    An analyst is investigating a malware infection. The file system timeline shows that a file 'svchost.exe' was created in the 'C:\Windows\System32' directory at 03:00:00 UTC. The Security event log shows a service installation event at 03:00:05 UTC. The file's $STANDARD_INFORMATION creation time is 03:00:00 UTC, and its modification time is 03:00:10 UTC. The analyst also finds that the file's digital signature is invalid. Which conclusion is best supported?

    Select an answer first
  3. 3application · medium

    An analyst is building a timeline from a Windows 10 system image. The user's Documents folder contains a file that was created on Monday, but the $STANDARD_INFORMATION (SI) creation timestamp shows Sunday. The $FILE_NAME (FN) creation timestamp shows Monday. The analyst needs to determine which timestamp reflects the actual file creation for the investigation. What should the analyst do?

    Select an answer first
  4. 4foundation · easy

    In NTFS, which metadata attribute contains the MAC times that are most commonly modified by the operating system when a file is accessed or changed?

    Select an answer first
  5. 5application · medium

    An analyst is examining a timeline of file system activity from a compromised Linux server. The timeline contains thousands of entries, and the analyst needs to identify files that were modified during the suspected breach window (02:00–03:00 UTC). Which technique is most effective for isolating relevant entries?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.