Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic analyst finds a suspicious .plist file in /Library/LaunchDaemons/ on a macOS system. The file contains a key "ProgramArguments" with a path to a script in /tmp. Which persistence mechanism does this indicate?

⚠ Common exam trap

EC-Council often tests the distinction between launch daemons (system-wide, in /Library/LaunchDaemons/) and launch agents (per-user, in ~/Library/LaunchAgents/), and candidates may confuse the two or incorrectly associate .plist files with cron jobs or login items.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Launch daemon

The .plist file located in /Library/LaunchDaemons/ with a 'ProgramArguments' key pointing to a script in /tmp is the standard configuration for a launch daemon. Launch daemons are system-wide background processes managed by launchd, and they are defined by plist files in /Library/LaunchDaemons/ (for system-wide daemons) or /System/Library/LaunchDaemons/ (for Apple-provided daemons). The presence of 'ProgramArguments' specifies the executable or script to run, making this a classic launch daemon persistence mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cron job

    Why it's wrong here

    A cron job is scheduled through crontab entries or launchd's StartCalendarInterval key, not through a ProgramArguments array pointing at an executable. The LaunchDaemons plist with ProgramArguments and RunAtLoad indicates a launch daemon executing a script at boot, which is the actual persistence mechanism. Cron would be the answer if the artefact were a crontab file or a periodic calendar-triggered job.

  • ✓

    Launch daemon

    Why this is correct

    A LaunchDaemon is defined by a plist placed in either /Library/LaunchDaemons/ (system-wide) or /System/Library/LaunchDaemons/ (Apple-sanctioned system services). These plists contain keys such as ProgramArguments, RunAtLoad, and KeepAlive, and launchd loads them during boot to execute services with root privileges, independent of any user session. A suspicious plist in the Library is therefore most consistent with a LaunchDaemon, especially if it resides in the LaunchDaemons subdirectory and lacks a user-specific component.

  • ✗

    Login item

    Why it's wrong here

    Login items are user-level startup entries that launch after a user logs into a GUI session, not system-wide boot services. They are recorded in a single Apple-preference file, ~/Library/Preferences/com.apple.loginitems.plist, or via the user's LaunchAgents (~/Library/LaunchAgents/), and are specific to the logged-in user. A plist found in a general Library path (e.g., /Library/LaunchDaemons) is therefore not a login item, as it would be outside the user's domain and wouldn't have the required per-user context.

  • ✗

    Kernel extension

    Why it's wrong here

    Kernel extensions (kexts) are actually bundles—directories ending in .kext that contain a binary executable, an Info.plist, and other resources, residing in /System/Library/Extensions or /Library/Extensions. The plist is merely an internal configuration file embedded inside the kext bundle; a standalone plist file cannot be loaded as a kernel module. On macOS (especially with SIP and the move to KDK extensions), kexts are loaded by the kernel at boot, not by launchd, so a suspicious plist in a Library folder is not a kext but likely a launchd job.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.