CHFI OS and Network Forensics Practice Question
A forensic analyst finds a file with the .plist extension on a Mac system. What type of artifact is this?
⚠ Common exam trap
The CHFI exam often tests the misconception that .plist files are log files because they store application data, but they are specifically property list files used for configuration and preferences, not event logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Property list file
The .plist extension stands for 'property list', a structured data file used by macOS and iOS applications to store serialized objects like configuration settings, user preferences, and application state. These files are XML or binary-encoded and are a key artifact in forensic analysis for recovering user activity, application usage, and system configuration. Option D is correct because .plist files are explicitly defined as property list files in Apple's developer documentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Log file
Why it's wrong here
Log files on macOS are not stored with a .plist extension; the unified logging system uses .log, .tracev3, or legacy .asl files that contain timestamped entries, not structured key-value pairs. A .plist (property list) file is a serialized data structure for configuration or data persistence, lacking the sequential, append-oriented format of a log. Thus, a file named with .plist cannot be a log file.
- ✗
Executable binary
Why it's wrong here
Executable code on macOS is typically a Mach-O binary (found in /usr/bin or inside .app bundles) or a script, none of which use the .plist extension. A .plist file is a data file that the system or an application reads, not something the kernel or shell executes directly. Moreover, executables have the executable permission bit set and a Mach-O header, whereas a .plist begins with an XML declaration or the binary 'bplist00' magic, making the distinction clear in forensic analysis.
- ✗
Email database
Why it's wrong here
Email databases are stored as .mbox or .eml files for message archives, or as mailbox index/database files (e.g., .db) on an email server; they do not use the .plist extension. A .plist is a generic serialization format used for preferences and configuration, not a container for email headers, bodies, or attachments. While a mail client might store its own settings in a plist, an actual mail database resides in these other containers, so .plist cannot represent it.
- ✓
Property list file
Why this is correct
A .plist (property list) file is Apple's structured serialization format for key-value pairs, arrays, and typed data, encoded as either XML or binary (with the 'bplist00' header). It is used pervasively for configuration—such as Info.plist for app metadata, preferences in ~/Library/Preferences, and app-specific data containers. The extension directly identifies this format, and forensic examiners routinely parse plists to extract settings, timestamps, and user activity, which is why this option is correct.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.