CHFI OS and Network Forensics Practice Question
Which Windows artifact is primarily used to determine the execution history of applications, including the path and run count?
⚠ Common exam trap
EC-CHFI often tests the distinction between artifacts that track execution history (Prefetch) versus those that track file access or user activity (LNK files, Jump Lists), so candidates mistakenly choose LNK files because they associate shortcuts with program launches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prefetch files
Prefetch files (.pf) are created by Windows to speed up application startup by caching data about the files loaded during the first few seconds of execution. Each prefetch file records the application's path, the number of times it has been run (run count), and the last execution timestamp, making it the primary artifact for determining execution history.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LNK files
Why it's wrong here
LNK files are Windows shortcut files that store a target path, icon location, and metadata such as the original file's creation and modification timestamps, as well as volume serial numbers. They are generated when a shortcut is created or used, but their presence does not prove the target executable was executed, nor do they track how many times an application ran. Forensic examiners use LNK files to demonstrate access to specific files or mounted volumes, not to establish an aggregate application execution history or run count.
- ✗
Jump lists
Why it's wrong here
Jump lists are a Windows feature, introduced in Windows 7, that maintain per-application lists of recently opened files, folders, or tasks. They are stored as .automaticDestinations-ms and .customDestinations-ms files under the user's Recent directory, and they provide rich MRU (most recently used) data with timestamps, but only for the application's destinations (e.g., documents opened in Word). Jump lists do not log every execution of the main executable itself, and they do not contain a run count or a cumulative execution timeline for the application. Therefore, they are valuable for file-access forensics, not for determining how often an application was launc…
- ✓
Prefetch files
Why this is correct
Prefetch files are generated by the Windows Prefetcher on each application launch to accelerate future startups by preloading referenced pages and DLLs. Each .pf file in C:\Windows\Prefetch contains the full executable path, a run count (stored at a specific offset in the header), the last execution timestamp, and a list of files accessed at startup. This makes Prefetch files the primary native artifact for determining the execution history, run count, and last run time of a specific application. They are especially powerful because they exist by default on desktop Windows installations, but forensic examiners should account for cases where Prefetch is disabled (e.g., on SSDs with certain configurations or via Group Policy).
- ✗
Event logs
Why it's wrong here
Windows Event Logs capture system, security, and application events such as service starts, failures, logon events, and error reports, but they do not natively record a generic 'process executed' event that logs every application launch with a path and run count. While advanced logging mechanisms like Sysmon can be configured to audit process creation (Event ID 1), the default event log infrastructure offers no aggregate execution counter or comprehensive run-history for all executables. Consequently, relying on event logs to answer 'how many times was this application run' is unreliable and incomplete, as they are designed for event auditing rather than per-execution tracking.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.