CHFI OS and Network Forensics Practice Question
In a Mac forensic investigation, which TWO artifacts are valuable for determining the timeline of file access? (Select two.)
⚠ Common exam trap
CHFI often tests the distinction between Windows-specific artifacts (ShellBags, Prefetch, NTUSER.DAT) and macOS-specific artifacts (Unified logging, FSEvents), so the trap here is assuming all forensic artifacts are cross-platform or that registry-based artifacts apply to macOS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unified logging
Unified logging (C) is correct because macOS's unified logging system (introduced in 10.12) stores system and application activity in .tracev3 files under /var/db/diagnostics, and its timestamps can establish when processes ran or files were touched, supporting timeline reconstruction. FSEvents (E) is correct because the FSEvents database (.fseventsd) records directory-level filesystem change events with timestamps, which is a core artifact for building a macOS file-access timeline. ShellBags (A) and NTUSER.DAT (D) are Windows artifacts (registry-based folder view settings and per-user registry hive, respectively) and do not exist on macOS. Prefetch files (B) are also a Windows artifact (C:\Windows\Prefetch) used for program execution analysis, not macOS file-access timelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ShellBags
Why it's wrong here
ShellBags are a Windows-only registry artifact that stores per-folder view settings, icon positions, window sizes, and timestamps for folders opened in Windows Explorer. The data lives in the user's USRCLASS.DAT and NTUSER.DAT registry hives, neither of which exists on macOS. They are therefore not recoverable from a Mac and indicate that the examiner is looking at the wrong operating system.
- ✗
Prefetch files
Why it's wrong here
Prefetch (.pf) files are a Windows performance-optimization artifact found in C:\Windows\Prefetch; they record the first executable and DLLs loaded on each application launch, giving examiners evidence of program execution. Their creation relies on the Windows Boot Manager and SuperFetch/ReadyBoost subsystems, which have no macOS equivalent. On a Mac, execution evidence is instead found in unified logging, Spotlight metadata, and launch services.
- ✓
Unified logging
Why this is correct
Unified logging is a macOS subsystem that captures structured, timestamped diagnostic messages from the kernel, processes, and user applications into binary .tracev3 stores under /var/db/diagnostics and /var/db/uuidtext. Investigators query it with log show or log stream to reconstruct file access, process execution, network activity, and system errors. It is a core native artifact on modern Macs and one of the two valid items in this question.
- ✗
NTUSER.DAT
Why it's wrong here
NTUSER.DAT is a Windows per-user registry hive that is loaded into HKEY_CURRENT_USER and contains configuration, MRU lists, user-assist execution counts, and third-party application settings. It is a central target in Windows forensics, but the macOS equivalent of user-level configuration is a set of property lists (plists) under ~/Library/Preferences, not a hive. Because the question asks about Mac artifacts, NTUSER.DAT is not applicable.
- ✓
FSEvents
Why this is correct
FSEvents is a macOS kernel-level mechanism that records file-system changes by writing append-only event streams to the .fseventsd directory on each volume. Each event record contains a path, event type, and event ID, enabling examiners to determine when files and directories were created, renamed, modified, or deleted on a Mac. It is a valid forensic artifact for Mac timeline analysis, especially when other logs are unavailable.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.