Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic examiner needs to analyze the contents of a Windows prefetch file (.pf) to determine the last execution time of an application. Which tool would BEST accomplish this task?

⚠ Common exam trap

Many candidates assume a built-in Windows tool named 'prefetch.exe' exists or confuse prefetch analysis with other Windows forensic artifacts like shell bags or jump lists, leading them to pick a plausible-sounding but incorrect option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PECmd

PECmd (Prefetch Explorer Command-line) is a dedicated forensic tool from Eric Zimmerman's suite designed specifically to parse Windows prefetch files (.pf). It extracts detailed metadata including the last execution time, run count, and referenced files, making it the best choice for this task. Built-in Windows tools do not provide a 'prefetch.exe' utility, and other options like ShellBags Explorer or JumpLister target different artifacts (registry shell bags and jump lists, respectively).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    prefetch.exe (built‑in Windows tool)

    Why it's wrong here

    There is no built-in Windows utility called 'prefetch.exe' — the Prefetch folder (%SystemRoot%\Prefetch) contains only .pf data files generated by the operating system when applications run. As a result, an examiner cannot execute a native program with this name to parse prefetch artifacts; instead, you must use a dedicated third-party parser or manually interpret the binary structure. Choosing this option reflects confusion between the system artifact itself and the tools used to decode it.

  • ✗

    ShellBags Explorer

    Why it's wrong here

    ShellBags Explorer is a forensic tool that parses the ShellBags registry values stored under HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell. Those registry keys record Explorer folder view settings such as window size, icon layout, and sort order, which can indicate which folders a user browsed. However, ShellBags contain no information about program execution timestamps, run counts, or referenced DLLs, so they are entirely unrelated to prefetch file analysis.

  • ✓

    PECmd

    Why this is correct

    PECmd (Prefetch Explorer Command-Line) is a free and widely accepted tool by Eric Zimmerman that parses Windows Prefetch (.pf) files. It extracts the executable's last run time, run count, and the list of referenced files and DLLs, exporting the results to CSV, HTML, or JSON for further triage. Because it stabilizes and standardizes prefetch decoding, it is the recommended option when an examiner needs to prove which binaries executed on a system.

  • ✗

    JumpLister

    Why it's wrong here

    JumpLister is a forensic utility that parses Windows jump lists, specifically the .automaticDestinations-ms and .customDestinations-ms files located under %AppData%\Microsoft\Windows\Recent. Jump lists reveal user-driven tasks like recent documents and applications pinned or accessed from the taskbar, which is a different artifact category from prefetch. Therefore, while JumpLister is useful for user activity analysis, it cannot parse the binary prefetch cache and should not be used for execution history.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.