CHFI Storage Forensics and File System Analysis Practice Question
Which file system artifact in NTFS records file system events such as file creation, deletion, and modification, and is often used to track attacker activities?
⚠ Common exam trap
The CHFI exam often tests the distinction between file-system-level journals (USN Journal) and higher-level logs (Event Logs), so candidates mistakenly choose Event Logs because they associate 'events' with Windows Event Viewer, not realizing the USN Journal is the specific NTFS artifact for file operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
USN Journal
The USN (Update Sequence Number) Journal is a native NTFS feature that logs all changes to files and directories on a volume, including creation, deletion, and modification events. Forensic analysts use it to reconstruct timelines of attacker activity because it records the reason for the change (e.g., USN_REASON_FILE_CREATE, USN_REASON_FILE_DELETE) along with timestamps and file references, even if the file is later deleted or renamed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event Logs
Why it's wrong here
Event Logs record system-wide operational, security, and application events, but they are not NTFS filesystem-format metadata. While an event such as a volume mount or disk error may appear in the System log, routine per-file or per-directory changes (like a rename or data append) are not written there unless explicitly enabled via auditing policies, which are disabled by default and resource-intensive. Thus, they are an indirect and incomplete source of filesystem activity, not a native artifact of NTFS itself.
- ✗
Prefetch files
Why it's wrong here
Prefetch files are forensic artifacts used solely to accelerate application startup by caching referenced DLLs and memory-mapped files in a .pf file under C:\Windows\Prefetch. They record only the executable's path, its last run time, and a list of files loaded during that specific process launch — not every filesystem mutation. Any modification to a document, creation of a folder, or metadata change to a non-executable file passes entirely unobserved, making Prefetch samples of process execution rather than an index of filesystem events.
- ✓
USN Journal
Why this is correct
The USN Journal (Update Sequence Number Journal) is a native NTFS feature that persistently records every change to files and directories on the volume, including creation, deletion, renaming, attribute changes, and data writes, each tagged with a monotonically increasing USN. It functions as a change journal that applications can query for backup, search indexing, and forensic reconstruction, and it exists even when Windows auditing is off. Because it resides in NTFS metadata ($Extend\$UsnJrnl) and tracks all filesystem modifications regardless of the user-mode API used, it is the definitive artifact for file system event activity.
- ✗
Registry
Why it's wrong here
The Registry is a hierarchical configuration database storing system settings, driver parameters, software preferences, and user profile details; it does not log file system operations by design. Although certain registry keys like UserAssist, MUICache, or MRU lists reflect indirect user activity and file access, those are application-dependent hints, not a comprehensive or reliable record of every file change. No driver automatically writes a new registry value for each NTFS event, so the Registry offers only selective, circumstantial clues about file interaction, making it fundamentally unsuitable as a filesystem event log.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.