Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

In Linux forensics, which file contains information about user account passwords in hashed form?

⚠ Common exam trap

Candidates often mistakenly think that /etc/passwd still contains password hashes, as it did in older Unix systems, but modern Linux distributions separate hashes into /etc/shadow for security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/shadow

In Linux, the /etc/shadow file stores user account passwords in hashed form, along with password aging information. This file is readable only by root (or privileged processes) to prevent unauthorized access to password hashes, unlike /etc/passwd which is world-readable and historically stored hashes but now typically shows an 'x' placeholder. The hashes are generated using algorithms like SHA-512 (crypt $6$) or yescrypt, as specified in the shadow file format.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /etc/passwd

    Why it's wrong here

    In modern Linux systems, /etc/passwd is world-readable and contains user account metadata—username, UID, GID, home directory, and login shell—but the password field is a placeholder ('x' or '*') indicating the actual hash is elsewhere. The hashes originally lived in this file in early Unix, which let any local user read them and crack them offline; shifting them to /etc/shadow addressed that exposure. A forensic examiner uses passwd for account enumeration and to map accounts to UIDs, but it offers no credential material for hash extraction.

  • ✓

    /etc/shadow

    Why this is correct

    The /etc/shadow file stores the actual hashed password for each local user, along with password-aging metadata such as the date of last change, minimum and maximum age, warning period, and account expiration. Access is restricted to root and the shadow group, so its 0640 (or 0000) permissions prevent ordinary users from harvesting hashes for offline brute-force attacks. In a forensic acquisition, this file is a primary source for credential recovery—tools like unshadow combine passwd and shadow to feed hash-cracking utilities like John the Ripper or hashcat.

  • ✗

    /etc/group

    Why it's wrong here

    The /etc/group file defines group accounts: group name, GID, a group password field (normally 'x' or empty, and rarely used), and a comma-separated list of member users. Although it has a 'password' column, it stores group passwords only, not user account passwords; group passwords are deprecated and used with the obsolete newgrp command. Forensic examiners consult this file to reconstruct access-control boundaries and privilege associations, but it is irrelevant to extracting user authentication credentials.

  • ✗

    /var/log/auth.log

    Why it's wrong here

    On Debian/Ubuntu and related distributions, /var/log/auth.log records authentication-related events: successful and failed login attempts, sudo invocation, su switches, and user/service authentication activities. Its contents prove what happened, but they do not contain any password hashes or credential values—hashes are never logged to prevent accidental exposure. In forensics, the log helps timeline reconstruction and suspect behavior analysis, while the actual hash evidence remains solely in /etc/shadow (or an equivalent remote auth store).

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.