Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

A forensic analyst is examining a Windows system and wants to identify recently accessed files and programs. Which TWO artifacts should the analyst prioritize? (Select TWO.)

⚠ Common exam trap

EC-CHFI often tests the distinction between artifacts that record user activity (Jump Lists, Prefetch) versus those that record system-level events (Event ID 4624) or authentication data (SAM), leading candidates to mistakenly select Event ID 4624 because they associate 'logon' with 'access'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Jump Lists

Jump Lists (A) are correct because they are per-application AutomaticDestinations/CustomDestinations files stored under the user's AppData\Roaming\Microsoft\Windows\Recent\ folder that record recently and frequently opened files and programs, directly matching the goal of identifying recently accessed items. Prefetch files (C) are correct because Windows creates .pf files in C:\Windows\Prefetch that track program execution, including run counts and last-run timestamps, which reveal recently executed programs. Event ID 4624 (B) is a Security log entry for successful logons, showing account authentication rather than file or program access. System Restore points (D) are snapshots used for system rollback and do not directly enumerate recently accessed files or programs. The SAM registry hive (E) stores local user account and credential data, not recent file or program usage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Jump Lists

    Why this is correct

    Jump Lists are forensic artifacts stored in %APPDATA%\Microsoft\Windows\Recent\AutomaticDestinations and CustomDestinations. They maintain MRU (most recently used) lists of files and applications associated with particular AppUserModelIDs, capturing timestamps of when files were opened or saved. This makes them a direct source for determining recently accessed documents and corresponding applications on a per-user basis.

  • ✗

    Event ID 4624 logs

    Why it's wrong here

    Event ID 4624 in the Windows Security log records successful logon events, including the authentication protocol (e.g., NTLM or Kerberos), logon type (interactive, network, etc.), source IP, and the user account. While this can confirm that a user accessed the system, it provides no information about subsequent file-level activity or which applications were run. Thus, it cannot answer questions about recently accessed documents.

  • ✓

    Prefetch files

    Why this is correct

    Prefetch files, located in C:\Windows\Prefetch with a .pf extension, are created when applications are launched to speed up future startups by pre-loading code. Each prefetch file contains the executable path, run count, and a list of referenced files (including document paths in some cases). They are valuable for proving that a specific executable was executed, but their purpose is execution history rather than a comprehensive record of user file accesses.

  • ✗

    System Restore points

    Why it's wrong here

    System Restore points are snapshots of critical system files, the registry, and some user data (on select OS versions) used for reverting system state after failures or malware. They do not function as an audit trail of user actions, nor do they record the specific files a user opened or applications they used. Furthermore, restore points are created periodically or during system changes, not continuously, making them unsuitable for time-specific file access history

  • ✗

    SAM registry hive

    Why it's wrong here

    The SAM (Security Account Manager) registry hive, located at `HKEY_LOCAL_MACHINE\SAM`, stores locally defined user accounts and their password hashes (LAN Manager and NT hashes), which are used for authentication. It does not contain any information about file access, application execution, or user browsing behavior. Moreover, the SAM hive is locked by the system while running and its data is encrypted with the syskey, further limiting its forensic utility for activity reconstruction.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.