Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 3Objective 2

File System Timeline Artifact Analysis GCFA Practice Questions (Page 3)

Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
5concepts

Questions 11–15

  1. 11application · medium

    An investigator is building a timeline from a Windows 10 system image. The $STANDARD_INFORMATION (SI) timestamps for a suspicious executable show a creation time of 2024-03-10 08:15:22 UTC, but the $FILE_NAME (FN) timestamps show a creation time of 2024-03-10 08:15:25 UTC. The investigator also notices the SI modification time is 2024-03-11 14:02:11 UTC while the FN modification time is 2024-03-10 08:15:25 UTC. Which action should the investigator take to avoid a false conclusion about when the file was first created on the system?

    Select an answer first
  2. 12application · medium

    An analyst is examining an NTFS volume and needs to determine the original creation time of a file that was copied from another location. The file's $STANDARD_INFORMATION creation time is 2024-07-01 10:00:00 UTC, and the $FILE_NAME creation time is 2024-07-01 10:00:00 UTC. However, the analyst knows the file was copied from a USB drive. Which timestamp is most likely to reflect the original creation time on the source system?

    Select an answer first
  3. 13application · medium

    A forensic analyst is examining a file on an NTFS volume and notices that the $STANDARD_INFORMATION (SI) timestamps have been cleared (set to 0), but the $FILE_NAME (FN) timestamps are intact. What is the most likely explanation?

    Select an answer first
  4. 14foundation · easy

    An analyst is correlating file system events with system logs. Which type of log is most likely to provide evidence of a user executing a program that was recently created on the system?

    Select an answer first
  5. 15application · medium

    An analyst is using a timeline analysis tool to review a large dataset from a compromised system. The analyst wants to focus on files that were modified in the /etc directory on a Linux system during a specific time range. Which filtering and sorting strategy is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.