
GIAC Certified Forensic Analyst
Domain 3Objective 1
Introduction to File System Timeline Forensics GCFA Practice Questions (Page 5)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
4concepts
Questions 21–25
- 21
An analyst is examining a timeline and finds that a file's last access time is earlier than its creation time. This is an anomaly that could indicate what?
Select an answer first - 22
You are analyzing a timeline from a compromised Linux server. You see a file in /tmp that was created, modified, and accessed within a one-minute window, and then the file's access time was updated several times over the next hour. No user was logged in during that period. Which analysis step is most likely to reveal the cause?
Select an answer first - 23
What is the primary purpose of file system timeline forensics in a digital investigation?
Select an answer first - 24
When analyzing a file system timeline, what does a cluster of file modification times in a short window typically indicate?
Select an answer first - 25
A forensic examiner is working on a case involving a Linux server that uses the ext4 file system. The examiner needs to create a timeline that includes file metadata, directory entries, and journal data. The examiner has limited time and must choose a tool that can efficiently parse these sources. Which tool is best suited for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.