CHFI OS and Network Forensics Practice Question
In Linux forensics, which file contains information about user account passwords in hashed form?
⚠ Common exam trap
Candidates often mistakenly think that /etc/passwd still contains password hashes, as it did in older Unix systems, but modern Linux distributions separate hashes into /etc/shadow for security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/shadow
In Linux, the /etc/shadow file stores user account passwords in hashed form, along with password aging information. This file is readable only by root (or privileged processes) to prevent unauthorized access to password hashes, unlike /etc/passwd which is world-readable and historically stored hashes but now typically shows an 'x' placeholder. The hashes are generated using algorithms like SHA-512 (crypt $6$) or yescrypt, as specified in the shadow file format.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/passwd
Why it's wrong here
In modern Linux systems, /etc/passwd is world-readable and contains user account metadata—username, UID, GID, home directory, and login shell—but the password field is a placeholder ('x' or '*') indicating the actual hash is elsewhere. The hashes originally lived in this file in early Unix, which let any local user read them and crack them offline; shifting them to /etc/shadow addressed that exposure. A forensic examiner uses passwd for account enumeration and to map accounts to UIDs, but it offers no credential material for hash extraction.
- ✓
/etc/shadow
Why this is correct
The /etc/shadow file stores the actual hashed password for each local user, along with password-aging metadata such as the date of last change, minimum and maximum age, warning period, and account expiration. Access is restricted to root and the shadow group, so its 0640 (or 0000) permissions prevent ordinary users from harvesting hashes for offline brute-force attacks. In a forensic acquisition, this file is a primary source for credential recovery—tools like unshadow combine passwd and shadow to feed hash-cracking utilities like John the Ripper or hashcat.
- ✗
/etc/group
Why it's wrong here
The /etc/group file defines group accounts: group name, GID, a group password field (normally 'x' or empty, and rarely used), and a comma-separated list of member users. Although it has a 'password' column, it stores group passwords only, not user account passwords; group passwords are deprecated and used with the obsolete newgrp command. Forensic examiners consult this file to reconstruct access-control boundaries and privilege associations, but it is irrelevant to extracting user authentication credentials.
- ✗
/var/log/auth.log
Why it's wrong here
On Debian/Ubuntu and related distributions, /var/log/auth.log records authentication-related events: successful and failed login attempts, sudo invocation, su switches, and user/service authentication activities. Its contents prove what happened, but they do not contain any password hashes or credential values—hashes are never logged to prevent accidental exposure. In forensics, the log helps timeline reconstruction and suspect behavior analysis, while the actual hash evidence remains solely in /etc/shadow (or an equivalent remote auth store).
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.