Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic analyst examines a Mac system and runs "log show --predicate 'eventMessage contains "disk"' --last 1h" in Terminal. This command extracts Unified Log entries related to disk activity. Which macOS forensic artifact is the analyst MOST likely querying?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apple Unified Logging

The 'log show' command with --predicate queries the Apple Unified Logging system, which centralizes logs from various subsystems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    .plist files

    Why it's wrong here

    Property list (.plist) files are structured XML or binary files that store configuration settings and application state, such as preferences in ~/Library/Preferences. They are not a system log format; the log show command does not read or query plists. Its output comes from the unified logging system's compressed binary log archives, not from preference files.

  • ✗

    FSEvents

    Why it's wrong here

    FSEvents is a macOS filesystem change notification API that records file and directory modifications as event IDs in journal files like .fseventsd on each volume, managed by the fseventsd daemon. These journals serve Time Machine, Spotlight, and backup tools, but they are not part of the unified logging system. log show has no facility to parse FSEvents journal history; it only reads unified log entries, making FSEvents an incorrect answer.

  • ✗

    Core Storage logs

    Why it's wrong here

    Core Storage is the volume management framework underneath FileVault 2 full-disk encryption, organizing physical disks into logical volume groups with metadata stored privately. Although Core Storage and the Core Storage daemon may produce status messages or diagnostic output, those records are not captured in the unified logging system's dataset that log show searches. Investigators would inspect Core Storage state via diskutil cs or system logs, not through log show's unified-log query.

  • ✓

    Apple Unified Logging

    Why this is correct

    Apple Unified Logging is the centralized, high-volume logging architecture built into macOS Sierra and later, aggregating kernel, framework, and app messages into a compact binary format on disk (e.g., in /var/db/diagnostics/). The log show command is the primary interface to filter and extract these entries, accepting predicates for process, subsystem, and time range. This makes it the correct answer because log show exclusively queries the unified logging system, not property lists, filesystem event journals, or Core Storage metadata.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.