Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

A forensic analyst is investigating a Windows system and wants to identify recently executed programs. Which TWO artifacts should the analyst examine?

⚠ Common exam trap

Candidates often confuse artifacts that track file access (MRU lists, Jump lists) with those that track program execution (Prefetch, UserAssist), leading to incorrect selection of MRU lists or Jump lists as evidence of program execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prefetch files

Prefetch files (B) are correct because Windows stores execution metadata in C:\Windows\Prefetch as .pf files, recording the executable name, run count, and last-run timestamps, making them a primary artifact for proving program execution. UserAssist (C) is correct because it tracks GUI-based program launches via ROT13-encoded entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist, including run counts and last-execution times for user-initiated applications. MRU lists (A) only show recently accessed files or commands, not necessarily executed programs, so they are weaker execution evidence. ShellBags (D) record folder view settings and window positions, reflecting folder navigation rather than program execution. Jump lists (E) are tied to taskbar/application recent-item history and indicate files opened by an application, but they do not directly prove that a program itself was executed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MRU lists

    Why it's wrong here

    MRU (Most Recently Used) lists are registry values that record recently accessed files, commands, or searches, such as the RunMRU key for commands typed in the Run dialog. They do not systematically log program executions; instead, they reflect file or command usage, and while a typed executable path might imply execution, MRU lists are not a comprehensive or reliable execution artifact. Analysts use them to infer user activity and file knowledge, not to definitively establish that a specific application ran.

  • ✓

    Prefetch files

    Why this is correct

    Prefetch files are created in C:\Windows\Prefetch when an application executes on Windows, serving as a performance optimization. Each .pf file contains the executable path, run count, last run timestamp, and a list of loaded modules (DLLs), making it a primary artifact for directly recording program execution. This is the strongest evidence for determining which applications were launched, including historically executed programs, though it may be disabled on SSDs or under certain configurations.

  • ✓

    UserAssist

    Why this is correct

    UserAssist is a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist that tracks GUI-based program launches from Windows Explorer, such as starting apps from the Start Menu or desktop. It records the executable path, run count, and last execution time, with data obfuscated using ROT13 encryption. This artifact captures user-specific execution activity and complements Prefetch, but only covers programs launched via the GUI, not command-line or other non-GUI executions.

  • ✗

    ShellBags

    Why it's wrong here

    ShellBags are registry keys that store folder view settings, such as window size, icon layout, and display mode, for folders a user browses in Explorer. They are invaluable for tracing folder navigation history and reconstructing access to file system locations, including network shares or removable drives. However, ShellBags do not indicate program execution; they only reveal that a folder was opened or explored, providing no evidence that any executable file inside those folders was ever run.

  • ✗

    Jump lists

    Why it's wrong here

    Jump lists are artifacts stored in %APPDATA%\Microsoft\Windows\Recent\AutomaticDestinations and CustomDestinations that display recently accessed files for applications pinned to the taskbar or jump list. They link a file to a specific application and record when the file was opened, but they are file-centric and application-specific, not a general record of program executions. The presence of a jump list for an application does not prove the application itself was executed—only that a user accessed a file using that application's interface.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.