Cyber Forensics: File Systems, Artifacts and Timeline Analysis
Published:
Reviewed by Bismith B · 11 Jun 2026
Questions
30
Duration
30 min
Faculty-reviewed
0
Updated
09 Jun 2026
About this mock
This test covers the internals of FAT, NTFS and ext file systems as they apply to digital investigations: how metadata structures record file activity, how deleted files survive for recovery, and the mechanics of file carving and slack space analysis. It then turns to the rich artifact ecosystem on Windows systems, including the registry, prefetch files, the Master File Table, LNK files, browser history databases, and email storage formats. The final section addresses timeline construction and super-timeline analysis, the tools used to correlate artifacts across sources, and the anti-forensic techniques investigators routinely encounter. Questions are framed as applied scenarios and comparisons, requiring you to reason about what evidence survives, why it survives, and how an investigator would interpret it. A working knowledge of file-system data structures and forensic tooling is assumed throughout.
Sources & references
Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.
- cited in 11 questions
File System Forensic Analysis
Brian Carrier, Chapter 14: Ext2 and Ext3 Concepts
- cited in 6 questions
Windows Forensic Analysis Toolkit
Harlan Carvey, Chapter on AmCache and Program Execution
- cited in 6 questions
Digital Forensics with Open Source Tools
Altheide and Carvey, Chapter on Internet and Browser Forensics
- cited in 5 questions
Windows Registry Forensics
Harlan Carvey, Chapter on User Activity
- cited in 2 questions
Handbook of Digital Forensics and Investigation
Eoghan Casey (ed.), Chapter on Anti-Forensics and Steganography
How our mocks are built
Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.
Common questions
What does the Cyber Forensics: File Systems, Artifacts and Timeline Analysis mock cover?+
This test covers the internals of FAT, NTFS and ext file systems as they apply to digital investigations: how metadata structures record file activity, how deleted files survive for recovery, and the mechanics of file carving and slack space analysis. It then turns to the rich artifact ecosystem on Windows systems, including the registry, prefetch files, the Master File Table, LNK files, browser history databases, and email storage formats. The final section addresses timeline construction and s
How many questions and how long is the test?+
30 multiple-choice questions, 30 minutes total. Difficulty: hard. Tier: Premium.
Who is this mock for?+
Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Cyber Forensics. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.
Are the questions reviewed?+
Each question carries a verified source citation. Faculty review for individual questions is in progress.
Do I need an account to take this mock?+
Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.