Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic examiner is analyzing a Mac system and wants to review system logs that record various activities, including application launches and kernel events. Which logging system on macOS should be examined?

⚠ Common exam trap

EC-Council often tests the misconception that Console.app is a separate logging system, when in fact it is merely a GUI front-end to the same unified logging system, and candidates may overlook the 'log' command as the primary forensic tool for accessing raw log data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unified logging (log command)

Unified logging (log command) is the correct answer because macOS has consolidated all system and user-level logs into a single, high-performance unified logging system since macOS 10.12 (Sierra). This system captures kernel events, application launches, and other activities in a structured, binary format that can be queried using the 'log' command-line tool or the Console app. It is the primary and most comprehensive source for forensic analysis of system activity on modern macOS systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    .plist files

    Why it's wrong here

    Property list (.plist) files are structured preference/configuration containers (XML or binary), commonly found in ~/Library/Preferences and app bundles. They store application settings, registered services, and metadata, not the system's operational log events. While plists can hold timestamps or user activity footprints valuable to a forensic timeline, they do not constitute the centralized system logging mechanism for macOS process, kernel, or network events.

  • ✗

    FSEvents

    Why it's wrong here

    FSEvents is a macOS kernel-generated mechanism that records file system changes in per-volume journal files (e.g., .fseventsd), capturing creation, deletion, rename, and modification events. It is an excellent source for file activity timelines and digital forensic reconstruction of user file actions, but it does not collect general system logs such as process launches, authentication attempts, or network connections. Therefore, an examiner seeking a comprehensive system log source must look beyond FSEvents.

  • ✓

    Unified logging (log command)

    Why this is correct

    Unified logging is the correct source because macOS's centralized logging system, introduced in macOS 10.12, captures all system, process, kernel, and user-level log messages through the os_log API. The `log` command (e.g., `log show`, `log collect`, `log stream`) provides forensic access to these persisted logs, including the compressed .tracev3 files in `/var/db/diagnostics`. This data, complete with precise timestamps and metadata, is exactly what an examiner needs for analyzing system events on a modern Mac.

  • ✗

    Console.app logs

    Why it's wrong here

    Console.app is a graphical user interface application that displays and filters the unified log stream; it is a viewer, not a separate logging infrastructure. Opening Console.app does not produce or store additional logs, and it cannot capture events that were already purged. For forensic analysis, relying on Console.app alone is insufficient because the underlying data resides in the unified logging store, which must be queried via the `log` command for reliable, artifact-preserving acquisition.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.