
GIAC Certified Forensic Analyst
Domain 3Objective 2
File System Timeline Artifact Analysis GCFA Practice Questions (Page 3)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
Questions 11–15
- 11
An investigator is building a timeline from a Windows 10 system image. The $STANDARD_INFORMATION (SI) timestamps for a suspicious executable show a creation time of 2024-03-10 08:15:22 UTC, but the $FILE_NAME (FN) timestamps show a creation time of 2024-03-10 08:15:25 UTC. The investigator also notices the SI modification time is 2024-03-11 14:02:11 UTC while the FN modification time is 2024-03-10 08:15:25 UTC. Which action should the investigator take to avoid a false conclusion about when the file was first created on the system?
Select an answer first - 12
An analyst is examining an NTFS volume and needs to determine the original creation time of a file that was copied from another location. The file's $STANDARD_INFORMATION creation time is 2024-07-01 10:00:00 UTC, and the $FILE_NAME creation time is 2024-07-01 10:00:00 UTC. However, the analyst knows the file was copied from a USB drive. Which timestamp is most likely to reflect the original creation time on the source system?
Select an answer first - 13
A forensic analyst is examining a file on an NTFS volume and notices that the $STANDARD_INFORMATION (SI) timestamps have been cleared (set to 0), but the $FILE_NAME (FN) timestamps are intact. What is the most likely explanation?
Select an answer first - 14
An analyst is correlating file system events with system logs. Which type of log is most likely to provide evidence of a user executing a program that was recently created on the system?
Select an answer first - 15
An analyst is using a timeline analysis tool to review a large dataset from a compromised system. The analyst wants to focus on files that were modified in the /etc directory on a Linux system during a specific time range. Which filtering and sorting strategy is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.