Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

Which TWO of the following are Windows artifacts that can provide evidence of file execution, including timestamps and paths?

⚠ Common exam trap

The CHFI exam often tests the distinction between artifacts that directly record execution (Prefetch, LNK) versus those that store unrelated system data (SAM, Event ID 4720) or provide only indirect evidence (Pagefile.sys), leading candidates to confuse memory artifacts with structured execution logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prefetch files (*.pf)

Prefetch files (*.pf) are correct because Windows creates them in C:\Windows\Prefetch when applications execute, and each .pf file records the executable name, run count, last-run timestamps, and referenced file/directory paths, directly evidencing execution. LNK files are correct because Windows shortcut files, typically found in Recent Items, Office Recent, or Jump Lists, store the target path, volume information, and MAC timestamps of the referenced file, showing that a file was opened or executed. Event ID 4720 is not correct because it records user account creation in the Security log, not file execution. The SAM registry hive is not correct because it stores local account and group information, including password hashes, not execution evidence. Pagefile.sys is not correct because it is virtual memory swap space that may contain residual data but is not a structured artifact specifically recording file execution timestamps and paths.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event ID 4720

    Why it's wrong here

    This Windows Security event is generated on domain controllers or local systems when a new user account is created. It contains fields like the target account name, security identifier (SID), and the subject who created it, but it does not capture any information about program execution or process starts. Therefore, while useful for user account lifecycle auditing, Event ID 4720 is not an artifact that can prove or analyze the execution of an application.

  • ✗

    SAM registry hive

    Why it's wrong here

    The Security Accounts Manager (SAM) registry hive stores local user account credentials in a hashed format (e.g., NTLM hashes) and account policies. It does not record processes, loaded modules, or execution timestamps. Forensic investigators query the SAM to enumerate user accounts, reset credentials, or recover password hashes, but it yields no evidence about which programs were run on the system.

  • ✓

    Prefetch files (*.pf)

    Why this is correct

    Prefetch files are created by Windows for each executable launched from a non-readonly path (with Application Prefetching enabled) to speed up subsequent loads. They store the executable's file path, a hash of the path, the number of times it was run, the last run timestamp, and the list of files and devices accessed during the first few seconds of execution. These artifacts allow forensic analysts to determine whether a specific application was executed, when it was executed, and how frequently.

  • ✗

    Pagefile.sys

    Why it's wrong here

    Pagefile.sys is a system-managed paging file that holds memory pages temporarily to extend the system's virtual memory, so its content is highly transient and can include remnants of any process's data, but not a structured record of file execution. Unlike dedicated execution artifacts, it does not contain filenames, timestamps, or run counts; any data found there is a fragment of raw memory and not a deterministic indicator of execution. Therefore, it is not considered an execution artifact for forensic confirmation of application runs.

  • ✓

    LNK files

    Why this is correct

    Windows LNK (shortcut) files are created automatically when a user opens a document, executes a program, or accesses a removable drive, and they capture metadata about the target, including the originating machine ID, volume serial number, full path, and timestamps (created, last accessed, modified) of both the shortcut and the target file. Forensic examiners use `lnk` files to reconstruct user activity, demonstrate program execution, and trace file access events, especially when the original files have been deleted. They represent direct evidence that the referenced file was executed or accessed.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.