Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

In Mac forensics, which artifact stores system-wide and per-user application preferences, often used to determine configured settings and recently accessed files?

⚠ Common exam trap

EC-Council often tests the distinction between preference storage (.plist) and logging (Unified logging) or file system change tracking (FSEvents), leading candidates to confuse operational logs with persistent configuration artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

.plist files

In macOS, application and system preferences are stored in property list (.plist) files. These XML or binary files contain key-value pairs that define configured settings, default values, and recently accessed files (e.g., NSRecentDocuments). Forensic examiners parse .plist files to recover user behavior, application usage, and system configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Unified logging

    Why it's wrong here

    Unified logging captures system and application log messages for diagnostics, not structured preference keys or recently accessed files. It would be the right artefact for tracing kernel or process events during an incident timeline, but plist files hold the configuration settings this question asks about.

  • ✓

    .plist files

    Why this is correct

    Property list files encode application preferences as key-value pairs, storing both system-wide settings in /Library/Preferences and per-user settings in ~/Library/Preferences. This satisfies the stem's requirement to determine configured settings and recently accessed files, since plists also record recent items, window states and document history.

  • ✗

    Sqlite databases

    Why it's wrong here

    SQLite databases store structured application data such as browser history, messages and cookies, not the preference hierarchy itself. They would be the correct artefact when examining records inside a specific app's data store, but plist files hold the system-wide and per-user settings described.

  • ✗

    FSEvents

    Why it's wrong here

    FSEvents records filesystem change notifications over time, supporting timeline reconstruction rather than storing configuration values. It would be the correct artefact for proving when a file was created, modified or deleted, but preference settings and recently accessed files live in plist files.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.