CHFI OS and Network Forensics Practice Question
During a forensic examination of a macOS system, you find a file at /private/var/log/system.log and also notice a directory /private/var/db/diagnostics/. What is the significance of these locations?
⚠ Common exam trap
EC-Council often tests the misconception that all macOS logs are plain-text files, leading candidates to overlook the binary unified logging system stored in /private/var/db/diagnostics/.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The diagnostics directory contains binary log data from the unified logging system
/private/var/db/diagnostics/ stores binary log data from Apple's unified logging system (os_log), which is the primary logging mechanism in macOS since Yosemite. Unlike the plain-text /private/var/log/system.log, these binary logs capture high-fidelity, structured diagnostic data that can be queried using the `log` command (e.g., `log show --archive`). This directory is critical for forensic analysis of system events, crashes, and performance issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They are both plain-text log files used for system monitoring
Why it's wrong here
The diagnostic directory does not store plain-text logs. Instead, macOS's unified logging system writes binary data into files inside this directory, preventing straightforward text-based parsing. While plain-text logs like system.log are used for legacy system monitoring, this location is specifically reserved for the high-density binary log store.
- ✓
The diagnostics directory contains binary log data from the unified logging system
Why this is correct
The diagnostics directory is the on-disk repository for unified logging, introduced in macOS Sierra, where entries are stored in compressed binary tracev3 files. These files capture detailed event-level data with nanosecond timestamps, message metadata, and privacy-scoped redaction, making them a rich source for forensic timelines. Investigators typically query this store with the 'log' command, not with text editors.
- ✗
The diagnostics directory contains compressed archives of system.log
Why it's wrong here
System.log is a legacy plain-text file found in /var/log, and its rotated archives are compressed gzip files such as system.log.gz. The diagnostics directory, by contrast, holds no compressed archives of that text log; its contents are exclusively the binary unified logging store managed by the system. Confusing these two locations is a common pitfall when building a log-file inventory.
- ✗
These locations are remnants of third-party security software
Why it's wrong here
This directory is created and managed by Apple's own operating system as part of the native unified logging framework, not installed by any third-party product. While endpoint security and endpoint detection and response tools may read from or mirror this data, the directory itself is a stock macOS component. Treating it as an artifact of third-party software would misinterpret standard system behavior.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.