CHFI OS and Network Forensics Practice Question
Which TWO of the following are forensic artifacts found on macOS systems that can help reconstruct user activity?
⚠ Common exam trap
This question tests the distinction between Windows and macOS forensic artifacts. The trap is that candidates familiar with Windows forensics may incorrectly assume Prefetch files or Registry hives exist on macOS, or that Event ID 4624 has a macOS equivalent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
.plist files
Option A (.plist files) is correct because macOS stores application and system preferences, recent items, and user-activity metadata in property list files (often binary or XML) under ~/Library/Preferences and /Library/Preferences, which investigators can parse with plutil or plist editors to reconstruct user behavior. Option B (Unified logging) is correct because macOS's Unified Logging system (introduced in 10.12, accessed via the log command or log show) records detailed system, application, and user events in .tracev3 files under /var/db/diagnostics, providing a rich timeline of activity. Option C (Prefetch files) is incorrect because *.pf Prefetch files are a Windows artifact (C:\Windows\Prefetch) that does not exist on macOS. Option D (Registry hive files) is incorrect because the Windows Registry (e.g., NTUSER.DAT, SYSTEM, SAM) is not present on macOS, which uses plists and other stores instead. Option E (Event ID 4624) is incorrect because that is a Windows Security event log identifier for a successful logon, not a macOS forensic artifact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
.plist files
Why this is correct
Property list files on macOS are structured XML or binary files that store per-app preferences, recent item lists, window states, and other persistent configuration data. In forensic examinations, they are critical for attributing user activity because they often contain timestamps and device-specific identifiers, and can be decoded with `plutil` or `strings`. They serve as the macOS counterpart to the Windows Registry for configuration and usage artifacts.
- ✓
Unified logging
Why this is correct
Unified logging is macOS's centralized, high-volume logging framework that captures system, kernel, and application messages into a persistent, privacy-protected data store. Investigators can query these logs with `log show`, using predicates to filter by process, time range, or event type, enabling reconstruction of app launches, user logins, and network activity. Unlike simple text log files, entries may be encoded and require specialized decode commands, but they are a rich, native macOS artifact.
- ✗
Prefetch files (*.pf)
Why it's wrong here
Windows Prefetch files (.pf) are created automatically in C:\Windows\Prefetch to expedite application startup by recording the first-run time, run count, and referenced file paths. They are a Windows-specific forensic artifact used to determine program execution history, but macOS has no Prefetch mechanism. macOS instead relies on launchd services, plist launch records, and unified logging to capture equivalent execution evidence.
- ✗
Registry hive files
Why it's wrong here
The Windows Registry is a hierarchical database that stores system, software, and user configuration data in hive files such as SYSTEM, SOFTWARE, and NTUSER.DAT, located under C:\Windows\System32\config and user profile folders. It is a Windows-only artifact; macOS uses plists, the `defaults` system, and `launchd` plists for configuration. Therefore, registry hives are not found on a Mac and are an incorrect choice here.
- ✗
Event ID 4624
Why it's wrong here
Event ID 4624 is a Windows security event log identifier that records successful logons, including the logon type, account name, and source IP address. This identifier belongs exclusively to Windows Event Log (Security.evtx); macOS does not use event IDs. Mac logon activity is instead captured in unified logging and authentication records such as those in `/var/log` and the `log show --predicate 'eventMessage CONTAINS "logon"'` output.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.