CHFI OS and Network Forensics Practice Question
In Windows forensics, which artifact is used to track recently executed programs on a per-user basis?
⚠ Common exam trap
The CHFI exam often tests the distinction between system-wide artifacts (Prefetch) and per-user artifacts (UserAssist), and the trap here is that candidates confuse Prefetch's global execution tracking with UserAssist's user-specific logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UserAssist
UserAssist is a Windows registry key (under NTUSER.DAT) that records the execution count and last execution time of GUI-based programs for each user. It is specifically designed to track recently executed programs on a per-user basis, making it the correct artifact for this forensic question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Jump lists
Why it's wrong here
Jump lists are artifacts stored in C:\Users\<user>\AppData\Roaming\Microsoft\Windows\Recent and contain recently opened files for applications pinned to the taskbar. However, they only reflect document/file interactions tied to specific apps that support Windows 7+ jump lists, not a list of every program executed. Crucially, an application must be pinned or in recent list, and the data can be cleaned by user action or policy, making it an incomplete source for tracking all program executions.
- ✓
UserAssist
Why this is correct
UserAssist is a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist in NTUSER.DAT that logs each per-user program execution, recording a Run Counter and Last Execution Time. The subkeys are GUIDs representing specific application categories, and the values are ROT13 encoded in many Windows versions, which can be easily decoded by forensic tools. Because it is stored per-user in the user hive, it directly ties an executed binary to a specific user account, making it the primary artifact for investigating recently executed programs.
- ✗
ShellBags
Why it's wrong here
ShellBags are registry values stored in both NTUSER.DAT and UsrClass.dat that remember the view settings (position, size, icon layout) for each folder a user browses in Explorer. They are invaluable for reconstructing a user's folder navigation history, but they do not log the execution of binaries or applications. Thus, while ShellBags show which directories were accessed, they cannot reveal which programs were run, unlike UserAssist.
- ✗
Prefetch files
Why it's wrong here
Prefetch files (.pf) are created automatically in C:\Windows\Prefetch to reduce startup time by caching boot and application launch data; each file records the executable path and the number of times it was run, along with the last run timestamp. Prefetch is system-wide, meaning it aggregates launches across all users on the machine, and it only covers common programs executed from certain paths. Consequently, Prefetch can corroborate that an app was run, but it lacks per-user attribution, so it is not the artifact for tracking a specific user's recent program executions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.