
GIAC Certified Forensic Analyst
Domain 3Objective 3
NTFS Artifact Analysis GCFA Practice Questions (Page 1)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
16concepts
Questions 1–5
- 1
An examiner is attempting to recover a deleted file on an NTFS volume. The $Bitmap shows that clusters 1000-1003 are marked as allocated, but the $MFT entry for the deleted file indicates that its data runs point to clusters 1000-1003. Which action is most appropriate?
Select an answer first - 2
Which NTFS structure contains the volume serial number and the location of the MFT?
Select an answer first - 3
You are recovering files from a drive that had a folder encrypted with EFS. The user's profile and encryption certificates are unavailable. Which statement best describes the forensic impact on recovering the encrypted files?
Select an answer first - 4
An examiner is attempting to recover a deleted file on an NTFS volume. The $MFT entry for the deleted file is still present, but the $Bitmap shows that the clusters previously used by the file are now marked as allocated. Which action is most appropriate?
Select an answer first - 5
How does NTFS compression affect forensic recovery of file data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.