Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

During a forensic investigation, you find a file named ntuser.dat.LOG1 in a user's profile directory. What is the primary purpose of this file?

⚠ Common exam trap

Watch out — candidates often confuse the LOG1 file with a simple backup or a log of user activity like browsing history, when in fact it is a low-level transactional log for registry integrity, not a user-visible log file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It logs changes to the user's registry hive for recovery purposes

The ntuser.dat.LOG1 file is a transactional log file used by the Windows registry to record changes made to the corresponding user's registry hive (ntuser.dat). Its primary purpose is to ensure data integrity and enable recovery of the hive in case of a system crash or power failure during a write operation, by allowing the registry to replay or roll back incomplete transactions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It contains the user's Internet browsing history

    Why it's wrong here

    NTUSER.DAT is the user-specific registry hive, not a browser artifact. Internet browsing history is persisted separately by the browser itself—e.g., in SQLite files like History under the profile folder or in Windows WebCacheV01.dat for Edge/IE. The NTUSER.DAT hive does track some typed URLs and run commands through MRU keys, but that is not browsing history; it is a registry log of user actions. Therefore, this option misidentifies the file's fundamental purpose.

  • ✓

    It logs changes to the user's registry hive for recovery purposes

    Why this is correct

    NTUSER.DAT.LOG1 is a transactional log file that records pending modifications to the NTUSER.DAT registry hive before they are committed to the main hive file. Windows uses these logs, along with .LOG2 and .REGISTRYMACHINE files, to replay incomplete writes and recover registry integrity after a crash or power failure. Forensically, the .LOG1 file can contain data that was never fully written to NTUSER.DAT, capturing recent changes that might not be present in the main hive. This is why the correct interpretation is that it logs changes for recovery, not a simple backup.

  • ✗

    It is a backup copy of the user's registry hive

    Why it's wrong here

    A backup copy would be a static snapshot of NTUSER.DAT at a point in time, such as from Volume Shadow Copy or a System Restore point. The .LOG1 file, by contrast, is a dynamic list of before-and-after values for registry keys that are part of an ongoing transaction, used to roll back or roll forward the hive's state. It does not contain a full copy of the entire hive, only the deltas for pending or recent operations. Thus it cannot restore the registry by itself; it works in conjunction with the main hive during transaction replay.

  • ✗

    It stores the user's recently accessed files

    Why it's wrong here

    Recently accessed files are recorded in Windows via Jump Lists (e.g., AutomaticDestinations custom destinations) and via MRU (Most Recently Used) lists stored in various registry keys within NTUSER.DAT (like Microsoft\Windows\CurrentVersion\Explorer\RecentDocs). The .LOG1 file does not store user activity lists; it only contains transaction data needed to ensure the integrity of the registry hive itself. Confusing the transaction log with user activity tracking is a common error—while both are associated with NTUSER.DAT, they serve entirely different roles.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.