
GIAC Certified Forensic Analyst
Domain 3Objective 3
NTFS Artifact Analysis GCFA Practice Questions (Page 6)
Part of the File System Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 7–12 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
16concepts
Questions 26–30
- 26
An examiner is analyzing an MFT entry and finds that the $FILE_NAME attribute is present but the $DATA attribute is missing. Which conclusion is most accurate?
Select an answer first - 27
You are validating the integrity of an NTFS volume image. The $Boot sector's 'Total Sectors' field does not match the size of the volume as reported by the partition table. What does this discrepancy most likely indicate?
Select an answer first - 28
How can the $LogFile be useful in a forensic investigation?
Select an answer first - 29
During a forensic review, you find a file named 'report.pdf' with an alternate data stream named 'hidden.txt'. The stream contains what appears to be a list of credentials. Which command would you use on a live Windows system to extract the contents of that stream to a file for analysis?
Select an answer first - 30
During a forensic examination, you need to identify the MFT entry number for a specific file. Which NTFS structure should you examine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.