CHFI OS and Network Forensics Practice Question
A forensic analyst is examining a Windows 10 system and finds suspicious activity. Which registry hive contains user-specific configuration data that can reveal evidence of recent file access through ShellBags, UserAssist, and MRU lists?
⚠ Common exam trap
A common misconception is that user-specific artifacts like ShellBags and UserAssist are stored in the HKLM\SOFTWARE hive because it contains application-related settings, but in reality, these are per-user and reside in the NTUSER.DAT hive (loaded as HKCU).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTUSER.DAT
The NTUSER.DAT file is the registry hive that stores user-specific configuration data for each user profile on a Windows 10 system. It contains the ShellBags keys (for folder view settings and recent folder access), UserAssist keys (tracking GUI-based program executions via the ROT13-encoded count and timestamp), and MRU (Most Recently Used) lists (for recently opened files and applications). These artifacts are critical for forensic analysis of user activity, and they are not stored in any of the HKLM hives, which are machine-wide.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HKLM\SYSTEM
Why it's wrong here
HKLM\SYSTEM hosts global boot and hardware configuration, including Control Sets, service start parameters, and the Registry values used during initialization. It does not track a user's application usage, file access, or explorer interactions. Its artifacts (e.g., MountedDevices) reflect system state, not the activity of a particular user account on the desktop.
- ✗
HKLM\SAM
Why it's wrong here
HKLM\SAM contains the Security Accounts Manager database, mapping local users and groups to SIDs and holding password hashes. While useful for credential forensics and account enumeration, it records neither file access, executed programs, nor browsing activity. Therefore it cannot answer the question of what a user did during a session.
- ✗
HKLM\SOFTWARE
Why it's wrong here
HKLM\SOFTWARE stores machine-wide application and operating system settings, such as installed programs, file type associations, and Windows components. Although certain SOFTWARE subkeys can expose last-run times for system services or Windows Update, user-specific ShellBags, UserAssist, and recent-document MRU lists reside in the per-user NTUSER.DAT hive. Thus HKLM\SOFTWARE lacks the personalized activity traces an examiner would rely on.
- ✓
NTUSER.DAT
Why this is correct
NTUSER.DAT is the per-user registry hive loaded as HKEY_CURRENT_USER at logon. It contains explorer shell bag state, UserAssist execution counts and last-run timestamps, RecentDocs MRU, and many user-profile settings. For Windows 10 analysis, this hive is the primary registry file for reconstructing a user's activity and program execution.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.