Courseiva
OS and Network Forensics →easyMultiple Select

CHFI OS and Network Forensics Practice Question

During a Windows forensic investigation, an analyst finds prefetch files with the .pf extension. Which TWO pieces of information can the analyst obtain from analyzing prefetch files?

⚠ Common exam trap

A common misconception is that prefetch files contain user-specific data or command-line arguments, but they only store execution count and timestamps, not user identity or process invocation details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The number of times the application has been executed

Prefetch files (.pf) in Windows record execution metadata for applications, and option A is correct because each prefetch file stores an execution count showing how many times the application has been run. Option B is also correct because prefetch files contain timestamps, including the last execution time and, in many versions, up to eight previous execution times, allowing an analyst to determine when the application was executed. These timestamps are stored in the prefetch file's metadata and are a core reason prefetch analysis is valuable in forensics. Option C is not correct because prefetch files do not record the username that executed the application; that information is typically found in other artifacts such as Security event logs or UserAssist. Option D is not correct because command-line arguments are not stored in prefetch files; they are more commonly recovered from process execution artifacts like ShimCache, AmCache, or event logs. Option E is not correct because prefetch files do not contain network connection data such as IP addresses; those would be found in network artifacts or logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The number of times the application has been executed

    Why this is correct

    Prefetch files record an execution count in their header, incremented each time the associated application runs. This directly satisfies the stem's requirement for execution frequency, letting the analyst establish how often a suspect binary or tool was launched on the Windows system under investigation.

  • ✓

    The exact date and time of each execution

    Why this is correct

    Prefetch files embed execution timestamps within their metadata, recording when each application last ran. This satisfies the investigator's need to establish execution chronology on the Windows host. The .pf format stores up to eight run times, letting the analyst correlate application launches with other artefacts during timeline reconstruction.

  • ✗

    The username that executed the application

    Why it's wrong here

    Prefetch files record execution counts, timestamps and referenced file paths and volumes, but not the account that ran the executable. User attribution comes from Security event logs or ShimCache and Amcache artefacts. Prefetch would be correct if the question asked about application launch times or loaded modules.

  • ✗

    The command-line arguments used to launch the program

    Why it's wrong here

    Prefetch stores the executable name, run count and timestamps, but never the command line passed to the process. It is tempting because prefetch proves execution, so analysts assume launch parameters are captured too; those arguments instead appear in Security event log 4688 or Sysmon Event ID 1.

  • ✗

    The IP addresses the application connected to

    Why it's wrong here

    Prefetch contains no network telemetry; it records file and execution metadata only. It is tempting because execution evidence often implies follow-on activity, but destination IP addresses must be recovered from network artefacts such as packet captures, firewall logs, or Sysmon Event ID 3, not from .pf files.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.