CHFI OS and Network Forensics Practice Question
A forensic analyst examines a Mac system and runs "log show --predicate 'eventMessage contains "disk"' --last 1h" in Terminal. This command extracts Unified Log entries related to disk activity. Which macOS forensic artifact is the analyst MOST likely querying?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apple Unified Logging
The 'log show' command with --predicate queries the Apple Unified Logging system, which centralizes logs from various subsystems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
.plist files
Why it's wrong here
Property list (.plist) files are structured XML or binary files that store configuration settings and application state, such as preferences in ~/Library/Preferences. They are not a system log format; the log show command does not read or query plists. Its output comes from the unified logging system's compressed binary log archives, not from preference files.
- ✗
FSEvents
Why it's wrong here
FSEvents is a macOS filesystem change notification API that records file and directory modifications as event IDs in journal files like .fseventsd on each volume, managed by the fseventsd daemon. These journals serve Time Machine, Spotlight, and backup tools, but they are not part of the unified logging system. log show has no facility to parse FSEvents journal history; it only reads unified log entries, making FSEvents an incorrect answer.
- ✗
Core Storage logs
Why it's wrong here
Core Storage is the volume management framework underneath FileVault 2 full-disk encryption, organizing physical disks into logical volume groups with metadata stored privately. Although Core Storage and the Core Storage daemon may produce status messages or diagnostic output, those records are not captured in the unified logging system's dataset that log show searches. Investigators would inspect Core Storage state via diskutil cs or system logs, not through log show's unified-log query.
- ✓
Apple Unified Logging
Why this is correct
Apple Unified Logging is the centralized, high-volume logging architecture built into macOS Sierra and later, aggregating kernel, framework, and app messages into a compact binary format on disk (e.g., in /var/db/diagnostics/). The log show command is the primary interface to filter and extract these entries, accepting predicates for process, subsystem, and time range. This makes it the correct answer because log show exclusively queries the unified logging system, not property lists, filesystem event journals, or Core Storage metadata.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.