CHFI OS and Network Forensics Practice Question
Which TWO of the following are Windows artifacts that can provide evidence of file execution, including timestamps and paths?
⚠ Common exam trap
The CHFI exam often tests the distinction between artifacts that directly record execution (Prefetch, LNK) versus those that store unrelated system data (SAM, Event ID 4720) or provide only indirect evidence (Pagefile.sys), leading candidates to confuse memory artifacts with structured execution logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prefetch files (*.pf)
Prefetch files (*.pf) are correct because Windows creates them in C:\Windows\Prefetch when applications execute, and each .pf file records the executable name, run count, last-run timestamps, and referenced file/directory paths, directly evidencing execution. LNK files are correct because Windows shortcut files, typically found in Recent Items, Office Recent, or Jump Lists, store the target path, volume information, and MAC timestamps of the referenced file, showing that a file was opened or executed. Event ID 4720 is not correct because it records user account creation in the Security log, not file execution. The SAM registry hive is not correct because it stores local account and group information, including password hashes, not execution evidence. Pagefile.sys is not correct because it is virtual memory swap space that may contain residual data but is not a structured artifact specifically recording file execution timestamps and paths.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event ID 4720
Why it's wrong here
This Windows Security event is generated on domain controllers or local systems when a new user account is created. It contains fields like the target account name, security identifier (SID), and the subject who created it, but it does not capture any information about program execution or process starts. Therefore, while useful for user account lifecycle auditing, Event ID 4720 is not an artifact that can prove or analyze the execution of an application.
- ✗
SAM registry hive
Why it's wrong here
The Security Accounts Manager (SAM) registry hive stores local user account credentials in a hashed format (e.g., NTLM hashes) and account policies. It does not record processes, loaded modules, or execution timestamps. Forensic investigators query the SAM to enumerate user accounts, reset credentials, or recover password hashes, but it yields no evidence about which programs were run on the system.
- ✓
Prefetch files (*.pf)
Why this is correct
Prefetch files are created by Windows for each executable launched from a non-readonly path (with Application Prefetching enabled) to speed up subsequent loads. They store the executable's file path, a hash of the path, the number of times it was run, the last run timestamp, and the list of files and devices accessed during the first few seconds of execution. These artifacts allow forensic analysts to determine whether a specific application was executed, when it was executed, and how frequently.
- ✗
Pagefile.sys
Why it's wrong here
Pagefile.sys is a system-managed paging file that holds memory pages temporarily to extend the system's virtual memory, so its content is highly transient and can include remnants of any process's data, but not a structured record of file execution. Unlike dedicated execution artifacts, it does not contain filenames, timestamps, or run counts; any data found there is a fragment of raw memory and not a deterministic indicator of execution. Therefore, it is not considered an execution artifact for forensic confirmation of application runs.
- ✓
LNK files
Why this is correct
Windows LNK (shortcut) files are created automatically when a user opens a document, executes a program, or accesses a removable drive, and they capture metadata about the target, including the originating machine ID, volume serial number, full path, and timestamps (created, last accessed, modified) of both the shortcut and the target file. Forensic examiners use `lnk` files to reconstruct user activity, demonstrate program execution, and trace file access events, especially when the original files have been deleted. They represent direct evidence that the referenced file was executed or accessed.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.