Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic analyst is examining a Windows 10 system and finds suspicious activity. Which registry hive contains user-specific configuration data that can reveal evidence of recent file access through ShellBags, UserAssist, and MRU lists?

⚠ Common exam trap

A common misconception is that user-specific artifacts like ShellBags and UserAssist are stored in the HKLM\SOFTWARE hive because it contains application-related settings, but in reality, these are per-user and reside in the NTUSER.DAT hive (loaded as HKCU).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NTUSER.DAT

The NTUSER.DAT file is the registry hive that stores user-specific configuration data for each user profile on a Windows 10 system. It contains the ShellBags keys (for folder view settings and recent folder access), UserAssist keys (tracking GUI-based program executions via the ROT13-encoded count and timestamp), and MRU (Most Recently Used) lists (for recently opened files and applications). These artifacts are critical for forensic analysis of user activity, and they are not stored in any of the HKLM hives, which are machine-wide.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKLM\SYSTEM

    Why it's wrong here

    HKLM\SYSTEM hosts global boot and hardware configuration, including Control Sets, service start parameters, and the Registry values used during initialization. It does not track a user's application usage, file access, or explorer interactions. Its artifacts (e.g., MountedDevices) reflect system state, not the activity of a particular user account on the desktop.

  • ✗

    HKLM\SAM

    Why it's wrong here

    HKLM\SAM contains the Security Accounts Manager database, mapping local users and groups to SIDs and holding password hashes. While useful for credential forensics and account enumeration, it records neither file access, executed programs, nor browsing activity. Therefore it cannot answer the question of what a user did during a session.

  • ✗

    HKLM\SOFTWARE

    Why it's wrong here

    HKLM\SOFTWARE stores machine-wide application and operating system settings, such as installed programs, file type associations, and Windows components. Although certain SOFTWARE subkeys can expose last-run times for system services or Windows Update, user-specific ShellBags, UserAssist, and recent-document MRU lists reside in the per-user NTUSER.DAT hive. Thus HKLM\SOFTWARE lacks the personalized activity traces an examiner would rely on.

  • ✓

    NTUSER.DAT

    Why this is correct

    NTUSER.DAT is the per-user registry hive loaded as HKEY_CURRENT_USER at logon. It contains explorer shell bag state, UserAssist execution counts and last-run timestamps, RecentDocs MRU, and many user-profile settings. For Windows 10 analysis, this hive is the primary registry file for reconstructing a user's activity and program execution.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.