Courseiva

CHFI Storage Forensics and File System Analysis Practice Question

Which file system artifact in NTFS records file system events such as file creation, deletion, and modification, and is often used to track attacker activities?

⚠ Common exam trap

The CHFI exam often tests the distinction between file-system-level journals (USN Journal) and higher-level logs (Event Logs), so candidates mistakenly choose Event Logs because they associate 'events' with Windows Event Viewer, not realizing the USN Journal is the specific NTFS artifact for file operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

USN Journal

The USN (Update Sequence Number) Journal is a native NTFS feature that logs all changes to files and directories on a volume, including creation, deletion, and modification events. Forensic analysts use it to reconstruct timelines of attacker activity because it records the reason for the change (e.g., USN_REASON_FILE_CREATE, USN_REASON_FILE_DELETE) along with timestamps and file references, even if the file is later deleted or renamed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event Logs

    Why it's wrong here

    Event Logs record system-wide operational, security, and application events, but they are not NTFS filesystem-format metadata. While an event such as a volume mount or disk error may appear in the System log, routine per-file or per-directory changes (like a rename or data append) are not written there unless explicitly enabled via auditing policies, which are disabled by default and resource-intensive. Thus, they are an indirect and incomplete source of filesystem activity, not a native artifact of NTFS itself.

  • ✗

    Prefetch files

    Why it's wrong here

    Prefetch files are forensic artifacts used solely to accelerate application startup by caching referenced DLLs and memory-mapped files in a .pf file under C:\Windows\Prefetch. They record only the executable's path, its last run time, and a list of files loaded during that specific process launch — not every filesystem mutation. Any modification to a document, creation of a folder, or metadata change to a non-executable file passes entirely unobserved, making Prefetch samples of process execution rather than an index of filesystem events.

  • ✓

    USN Journal

    Why this is correct

    The USN Journal (Update Sequence Number Journal) is a native NTFS feature that persistently records every change to files and directories on the volume, including creation, deletion, renaming, attribute changes, and data writes, each tagged with a monotonically increasing USN. It functions as a change journal that applications can query for backup, search indexing, and forensic reconstruction, and it exists even when Windows auditing is off. Because it resides in NTFS metadata ($Extend\$UsnJrnl) and tracks all filesystem modifications regardless of the user-mode API used, it is the definitive artifact for file system event activity.

  • ✗

    Registry

    Why it's wrong here

    The Registry is a hierarchical configuration database storing system settings, driver parameters, software preferences, and user profile details; it does not log file system operations by design. Although certain registry keys like UserAssist, MUICache, or MRU lists reflect indirect user activity and file access, those are application-dependent hints, not a comprehensive or reliable record of every file change. No driver automatically writes a new registry value for each NTFS event, so the Registry offers only selective, circumstantial clues about file interaction, making it fundamentally unsuitable as a filesystem event log.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.