Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

In a Mac forensic investigation, which TWO artifacts are valuable for determining the timeline of file access? (Select two.)

⚠ Common exam trap

CHFI often tests the distinction between Windows-specific artifacts (ShellBags, Prefetch, NTUSER.DAT) and macOS-specific artifacts (Unified logging, FSEvents), so the trap here is assuming all forensic artifacts are cross-platform or that registry-based artifacts apply to macOS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unified logging

Unified logging (C) is correct because macOS's unified logging system (introduced in 10.12) stores system and application activity in .tracev3 files under /var/db/diagnostics, and its timestamps can establish when processes ran or files were touched, supporting timeline reconstruction. FSEvents (E) is correct because the FSEvents database (.fseventsd) records directory-level filesystem change events with timestamps, which is a core artifact for building a macOS file-access timeline. ShellBags (A) and NTUSER.DAT (D) are Windows artifacts (registry-based folder view settings and per-user registry hive, respectively) and do not exist on macOS. Prefetch files (B) are also a Windows artifact (C:\Windows\Prefetch) used for program execution analysis, not macOS file-access timelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ShellBags

    Why it's wrong here

    ShellBags are a Windows-only registry artifact that stores per-folder view settings, icon positions, window sizes, and timestamps for folders opened in Windows Explorer. The data lives in the user's USRCLASS.DAT and NTUSER.DAT registry hives, neither of which exists on macOS. They are therefore not recoverable from a Mac and indicate that the examiner is looking at the wrong operating system.

  • ✗

    Prefetch files

    Why it's wrong here

    Prefetch (.pf) files are a Windows performance-optimization artifact found in C:\Windows\Prefetch; they record the first executable and DLLs loaded on each application launch, giving examiners evidence of program execution. Their creation relies on the Windows Boot Manager and SuperFetch/ReadyBoost subsystems, which have no macOS equivalent. On a Mac, execution evidence is instead found in unified logging, Spotlight metadata, and launch services.

  • ✓

    Unified logging

    Why this is correct

    Unified logging is a macOS subsystem that captures structured, timestamped diagnostic messages from the kernel, processes, and user applications into binary .tracev3 stores under /var/db/diagnostics and /var/db/uuidtext. Investigators query it with log show or log stream to reconstruct file access, process execution, network activity, and system errors. It is a core native artifact on modern Macs and one of the two valid items in this question.

  • ✗

    NTUSER.DAT

    Why it's wrong here

    NTUSER.DAT is a Windows per-user registry hive that is loaded into HKEY_CURRENT_USER and contains configuration, MRU lists, user-assist execution counts, and third-party application settings. It is a central target in Windows forensics, but the macOS equivalent of user-level configuration is a set of property lists (plists) under ~/Library/Preferences, not a hive. Because the question asks about Mac artifacts, NTUSER.DAT is not applicable.

  • ✓

    FSEvents

    Why this is correct

    FSEvents is a macOS kernel-level mechanism that records file-system changes by writing append-only event streams to the .fseventsd directory on each volume. Each event record contains a path, event type, and event ID, enabling examiners to determine when files and directories were created, renamed, modified, or deleted on a Mac. It is a valid forensic artifact for Mac timeline analysis, especially when other logs are unavailable.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.