CHFI OS and Network Forensics Practice Question
In Mac forensics, which artifact stores system-wide and per-user application preferences, often used to determine configured settings and recently accessed files?
⚠ Common exam trap
EC-Council often tests the distinction between preference storage (.plist) and logging (Unified logging) or file system change tracking (FSEvents), leading candidates to confuse operational logs with persistent configuration artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
.plist files
In macOS, application and system preferences are stored in property list (.plist) files. These XML or binary files contain key-value pairs that define configured settings, default values, and recently accessed files (e.g., NSRecentDocuments). Forensic examiners parse .plist files to recover user behavior, application usage, and system configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unified logging
Why it's wrong here
Unified logging captures system and application log messages for diagnostics, not structured preference keys or recently accessed files. It would be the right artefact for tracing kernel or process events during an incident timeline, but plist files hold the configuration settings this question asks about.
- ✓
.plist files
Why this is correct
Property list files encode application preferences as key-value pairs, storing both system-wide settings in /Library/Preferences and per-user settings in ~/Library/Preferences. This satisfies the stem's requirement to determine configured settings and recently accessed files, since plists also record recent items, window states and document history.
- ✗
Sqlite databases
Why it's wrong here
SQLite databases store structured application data such as browser history, messages and cookies, not the preference hierarchy itself. They would be the correct artefact when examining records inside a specific app's data store, but plist files hold the system-wide and per-user settings described.
- ✗
FSEvents
Why it's wrong here
FSEvents records filesystem change notifications over time, supporting timeline reconstruction rather than storing configuration values. It would be the correct artefact for proving when a file was created, modified or deleted, but preference settings and recently accessed files live in plist files.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.