Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

Which TWO of the following are forensic artifacts found on macOS systems that can help reconstruct user activity?

⚠ Common exam trap

This question tests the distinction between Windows and macOS forensic artifacts. The trap is that candidates familiar with Windows forensics may incorrectly assume Prefetch files or Registry hives exist on macOS, or that Event ID 4624 has a macOS equivalent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

.plist files

Option A (.plist files) is correct because macOS stores application and system preferences, recent items, and user-activity metadata in property list files (often binary or XML) under ~/Library/Preferences and /Library/Preferences, which investigators can parse with plutil or plist editors to reconstruct user behavior. Option B (Unified logging) is correct because macOS's Unified Logging system (introduced in 10.12, accessed via the log command or log show) records detailed system, application, and user events in .tracev3 files under /var/db/diagnostics, providing a rich timeline of activity. Option C (Prefetch files) is incorrect because *.pf Prefetch files are a Windows artifact (C:\Windows\Prefetch) that does not exist on macOS. Option D (Registry hive files) is incorrect because the Windows Registry (e.g., NTUSER.DAT, SYSTEM, SAM) is not present on macOS, which uses plists and other stores instead. Option E (Event ID 4624) is incorrect because that is a Windows Security event log identifier for a successful logon, not a macOS forensic artifact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    .plist files

    Why this is correct

    Property list files on macOS are structured XML or binary files that store per-app preferences, recent item lists, window states, and other persistent configuration data. In forensic examinations, they are critical for attributing user activity because they often contain timestamps and device-specific identifiers, and can be decoded with `plutil` or `strings`. They serve as the macOS counterpart to the Windows Registry for configuration and usage artifacts.

  • ✓

    Unified logging

    Why this is correct

    Unified logging is macOS's centralized, high-volume logging framework that captures system, kernel, and application messages into a persistent, privacy-protected data store. Investigators can query these logs with `log show`, using predicates to filter by process, time range, or event type, enabling reconstruction of app launches, user logins, and network activity. Unlike simple text log files, entries may be encoded and require specialized decode commands, but they are a rich, native macOS artifact.

  • ✗

    Prefetch files (*.pf)

    Why it's wrong here

    Windows Prefetch files (.pf) are created automatically in C:\Windows\Prefetch to expedite application startup by recording the first-run time, run count, and referenced file paths. They are a Windows-specific forensic artifact used to determine program execution history, but macOS has no Prefetch mechanism. macOS instead relies on launchd services, plist launch records, and unified logging to capture equivalent execution evidence.

  • ✗

    Registry hive files

    Why it's wrong here

    The Windows Registry is a hierarchical database that stores system, software, and user configuration data in hive files such as SYSTEM, SOFTWARE, and NTUSER.DAT, located under C:\Windows\System32\config and user profile folders. It is a Windows-only artifact; macOS uses plists, the `defaults` system, and `launchd` plists for configuration. Therefore, registry hives are not found on a Mac and are an incorrect choice here.

  • ✗

    Event ID 4624

    Why it's wrong here

    Event ID 4624 is a Windows security event log identifier that records successful logons, including the logon type, account name, and source IP address. This identifier belongs exclusively to Windows Event Log (Security.evtx); macOS does not use event IDs. Mac logon activity is instead captured in unified logging and authentication records such as those in `/var/log` and the `log show --predicate 'eventMessage CONTAINS "logon"'` output.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.