CHFI OS and Network Forensics Practice Question
A forensics investigator finds a suspicious LNK file on a Windows system that points to a script located on a remote share. What is the PRIMARY forensic significance of this LNK file?
⚠ Common exam trap
It's easy for candidates to confuse LNK files with Prefetch artifacts or assume all LNK files indicate user activity, when in fact an LNK targeting a remote share is a strong signal of lateral movement via SMB/remote execution, not local execution or USB history.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It may be part of a lateral movement technique using remote execution.
An LNK file pointing to a remote share is a classic indicator of lateral movement, often used in techniques like SMB-based remote execution or PsExec. The LNK file itself does not execute code, but when opened, it triggers the Windows shell to connect to the remote share and run the script, allowing an attacker to move from one system to another without dropping a binary on the target. This is a key forensic artifact for identifying network-based propagation in attacks such as ransomware or APT intrusions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is evidence of USB device insertion.
Why it's wrong here
A .lnk file does not record USB device insertion events. USB insertion is captured in the Windows registry under keys such as SYSTEM\CurrentControlSet\Enum\USBSTOR and SYSTEM\CurrentControlSet\Services\USBStor, as well as in Setupapi.dev.log and the system event log. The presence of a shortcut file, even one pointing to a removable path, is not an insertion artifact; that inference would require correlating USB history from the registry and logging.
- ✓
It may be part of a lateral movement technique using remote execution.
Why this is correct
This is the correct interpretation: an .lnk file that points to a remote share or contains a UNC path (e.g., \\attacker-server\payload\.scr) is a recognized lateral movement technique. Attackers use LNK shortcuts as bootstrap payloads delivered through PsExec, scheduled tasks, or WMI, where the shortcut is written to a target host and triggers remote execution of a malicious script or binary. The shortcut's TargetPath and Arguments fields are the forensic keys to identifying this behavior.
- ✗
It shows the user's recently accessed files.
Why it's wrong here
While .lnk files in a user's Recent\AutomaticDestinations folder can indicate files that user accessed, a suspicious .lnk on a hardened or unattended system is not proof of user activity, and a shortcut with a remote target path is inconsistent with a simple 'recently accessed' artifact. The presence of network-oriented arguments or embedded PowerShell content shifts the interpretation away from passive document access toward active payload delivery. File system forensics should rely on shortcut target resolution, not assume every .lnk is a Recent item.
- ✗
It is a prefetch artifact indicating the script was executed.
Why it's wrong here
Prefetch files (.pf) are the Windows artifacts that record executable launch times and is not how LNK files function. A .lnk is only a shell shortcut; it is parsed by Explorer when the user double-clicks it, but creating a shortcut does not execute the target, and its mere existence does not prove the script ran. Execution evidence would come from the target process's prefetch entry, the associated script host's event logs, or Security auditing, not from the LNK file itself.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.