Windows Execution Artifacts: Prefetch, Jump Lists, and LNK Files
Which TWO of the following are valid artifacts for determining program execution on a Windows system? (Select TWO.)
Quick Answer
The answer is Prefetch files and Jump Lists. Prefetch files are valid artifacts because they store execution information for applications, including the last run time and run count, directly indicating program execution on a Windows system. Jump Lists complement this by tracking recent files opened by specific applications, thereby revealing usage patterns and confirming that a program was actively used. On the Computer Hacking Forensic Investigator CHFI exam, this tests your ability to distinguish between execution artifacts and mere presence artifacts like LNK files, which can be created without execution. A common trap is assuming all shortcut files prove execution, but only Prefetch and Jump Lists provide direct evidence of a program actually running. To remember, think of Prefetch as the “program’s memory” of being launched, and Jump Lists as the “user’s recent activity log” tied to that program.
⚠ Common exam trap
EC-Council often tests the distinction between artifacts that record normal execution (Prefetch, Jump Lists) versus those that capture system state or errors (Pagefile, Restore Points, WER logs), leading candidates to overestimate the forensic value of Pagefile.sys or System Restore points.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Jump Lists
Jump Lists (C) are valid artifacts because they are stored per-user in the AutomaticDestinations and CustomDestinations folders under %AppData%\Microsoft\Windows\Recent, and they record recently or frequently accessed files and applications, providing direct evidence of program execution. Prefetch files (D) are also valid because Windows creates a .pf file in C:\Windows\Prefetch for each executed application, containing the executable name, run count, and last-run timestamps, which directly demonstrates program execution. Pagefile.sys (A) is a virtual memory swap file, not an execution artifact, and System Restore points (B) are snapshots of system state used for rollback rather than proof of program execution. Windows Error Reporting logs (E) record crash and error telemetry, so they may indicate a program ran but are not a reliable or standard artifact for determining execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pagefile.sys
Why it's wrong here
Pagefile.sys holds swapped virtual-memory pages and may incidentally retain fragments, but it is not a structured execution artifact. It suits memory forensics and paging analysis, whereas program execution is evidenced by Prefetch, ShimCache, AmCache, or UserAssist.
- ✗
System Restore points
Why it's wrong here
Restore points store system state, not program execution details.
- ✓
Jump Lists
Why this is correct
Jump Lists record recently and frequently accessed files and applications per user, including entries created when programs launch. They therefore evidence program execution on Windows, satisfying the requirement for a valid execution artifact alongside Prefetch and similar records.
- ✓
Prefetch files
Why this is correct
Prefetch files record execution metadata for each application, storing the executable name, run count and last-run timestamps in C:\Windows\Prefetch. This directly satisfies the requirement to determine program execution on a Windows system, since the .pf files persist after the process terminates and evidence execution even when other traces have been cleared.
- ✗
Windows Error Reporting logs
Why it's wrong here
Windows Error Reporting logs record application crashes and fault events, not successful process launches, so they cannot evidence general program execution. They are tempting because they do capture some process-related activity, and would be the right artefact when investigating why a specific application crashed or faulted.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CHFI
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which Windows artifact is primarily used to determine the execution history of applications, including the path and run count?
easy- A.LNK files
- B.Jump lists
- ✓ C.Prefetch files
- D.Event logs
Why C: Prefetch files (.pf) are created by Windows to speed up application startup by caching data about the files loaded during the first few seconds of execution. Each prefetch file records the application's path, the number of times it has been run (run count), and the last execution timestamp, making it the primary artifact for determining execution history.
Variation 2. Which TWO of the following are Windows artifacts that can provide evidence of file execution, including timestamps and paths?
medium- A.Event ID 4720
- B.SAM registry hive
- ✓ C.Prefetch files (*.pf)
- D.Pagefile.sys
- ✓ E.LNK files
Why C: Prefetch files (*.pf) are correct because Windows creates them in C:\Windows\Prefetch when applications execute, and each .pf file records the executable name, run count, last-run timestamps, and referenced file/directory paths, directly evidencing execution. LNK files are correct because Windows shortcut files, typically found in Recent Items, Office Recent, or Jump Lists, store the target path, volume information, and MAC timestamps of the referenced file, showing that a file was opened or executed. Event ID 4720 is not correct because it records user account creation in the Security log, not file execution. The SAM registry hive is not correct because it stores local account and group information, including password hashes, not execution evidence. Pagefile.sys is not correct because it is virtual memory swap space that may contain residual data but is not a structured artifact specifically recording file execution timestamps and paths.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.