CHFI OS and Network Forensics Practice Question
A forensic examiner is analyzing a Mac system and wants to review system logs that record various activities, including application launches and kernel events. Which logging system on macOS should be examined?
⚠ Common exam trap
EC-Council often tests the misconception that Console.app is a separate logging system, when in fact it is merely a GUI front-end to the same unified logging system, and candidates may overlook the 'log' command as the primary forensic tool for accessing raw log data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unified logging (log command)
Unified logging (log command) is the correct answer because macOS has consolidated all system and user-level logs into a single, high-performance unified logging system since macOS 10.12 (Sierra). This system captures kernel events, application launches, and other activities in a structured, binary format that can be queried using the 'log' command-line tool or the Console app. It is the primary and most comprehensive source for forensic analysis of system activity on modern macOS systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
.plist files
Why it's wrong here
Property list (.plist) files are structured preference/configuration containers (XML or binary), commonly found in ~/Library/Preferences and app bundles. They store application settings, registered services, and metadata, not the system's operational log events. While plists can hold timestamps or user activity footprints valuable to a forensic timeline, they do not constitute the centralized system logging mechanism for macOS process, kernel, or network events.
- ✗
FSEvents
Why it's wrong here
FSEvents is a macOS kernel-generated mechanism that records file system changes in per-volume journal files (e.g., .fseventsd), capturing creation, deletion, rename, and modification events. It is an excellent source for file activity timelines and digital forensic reconstruction of user file actions, but it does not collect general system logs such as process launches, authentication attempts, or network connections. Therefore, an examiner seeking a comprehensive system log source must look beyond FSEvents.
- ✓
Unified logging (log command)
Why this is correct
Unified logging is the correct source because macOS's centralized logging system, introduced in macOS 10.12, captures all system, process, kernel, and user-level log messages through the os_log API. The `log` command (e.g., `log show`, `log collect`, `log stream`) provides forensic access to these persisted logs, including the compressed .tracev3 files in `/var/db/diagnostics`. This data, complete with precise timestamps and metadata, is exactly what an examiner needs for analyzing system events on a modern Mac.
- ✗
Console.app logs
Why it's wrong here
Console.app is a graphical user interface application that displays and filters the unified log stream; it is a viewer, not a separate logging infrastructure. Opening Console.app does not produce or store additional logs, and it cannot capture events that were already purged. For forensic analysis, relying on Console.app alone is insufficient because the underlying data resides in the unified logging store, which must be queried via the `log` command for reliable, artifact-preserving acquisition.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.