
GIAC Certified Forensic Analyst
Domain 3Objective 2
File System Timeline Artifact Analysis GCFA Practice Questions (Page 4)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
Questions 16–20
- 16
A forensic analyst is examining an NTFS volume and needs to determine when a specific file was last accessed. The analyst finds that the $STANDARD_INFORMATION last access time is 2024-05-01 10:00:00 UTC, but the $FILE_NAME last access time is 2024-04-28 09:00:00 UTC. The system has 'last access time update' disabled. Which timestamp should the analyst report as the most reliable last access time?
Select an answer first - 17
An examiner is working with a large timeline and needs to identify files that were accessed during a specific 15-minute window. The timeline contains millions of entries. Which technique is most efficient for this task?
Select an answer first - 18
What is the primary purpose of constructing a file system timeline during a forensic investigation?
Select an answer first - 19
During a forensic examination, an analyst needs to build a comprehensive timeline of file system activity. Which approach best describes the process of timeline creation?
Select an answer first - 20
An analyst has a large timeline of file system events and wants to focus on events that occurred during a specific two-hour window on a particular day. Which technique is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.