
GIAC Certified Forensic Analyst
Domain 3Objective 3
NTFS Artifact Analysis GCFA Practice Questions (Page 11)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
16concepts
Questions 51–55
- 51
You are recovering files from a volume that contains both compressed and encrypted files. A compressed file was deleted, and its clusters are now partially overwritten. An encrypted file was also deleted, but its MFT record is intact. Which file is more likely to be fully recoverable?
Select an answer first - 52
Which NTFS system file contains the USN Journal?
Select an answer first - 53
During an investigation, you locate a deleted file's MFT record in unallocated space. The record's sequence number is 5, but the $MFT's $STANDARD_INFORMATION attribute for the current directory entry shows the file was last referenced with sequence number 4. What does this discrepancy most likely indicate?
Select an answer first - 54
When analyzing NTFS timestamps, what does the 'C' in MACB stand for?
Select an answer first - 55
How can NTFS artifacts be correlated with Windows Event Logs to reconstruct user actions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.