CHFI OS and Network Forensics Practice Question
In Linux forensics, which file contains user account information including the user ID, group ID, home directory, and default shell?
⚠ Common exam trap
EC-CHFI often tests the distinction between /etc/passwd and /etc/shadow, trapping candidates who confuse the password storage location with the account information file, leading them to incorrectly select /etc/shadow because they associate it with user accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/passwd
The /etc/passwd file is the standard Linux user database that stores essential account details, including the username, user ID (UID), group ID (GID), home directory path, and default shell. Each line in this file corresponds to a user account and uses a colon-delimited format (e.g., username:x:UID:GID:comment:home:shell). This file is world-readable because it does not contain passwords (which are stored in /etc/shadow), making it the correct source for the information listed in the question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
/etc/passwd
Why this is correct
The /etc/passwd file is the traditional system account database in Linux, containing one colon-delimited entry per user account. Each line includes the username, a password placeholder (usually x), user ID, group ID, GECOS description, home directory, and default login shell. This file is the authoritative source for identifying which accounts exist on a system during forensic analysis. Password hashes themselves are stored separately in /etc/shadow, not here.
- ✗
/var/log/auth.log
Why it's wrong here
/var/log/auth.log is a system logging file that records authentication-related events such as successful and failed logins, sudo command executions, and SSH sessions. It does not define user accounts; rather, it provides a historical trail of when and how accounts were used. A forensic examiner might examine this file to reconstruct user activity, but the actual user account details like UID and home directory come from /etc/passwd.
- ✗
/etc/shadow
Why it's wrong here
The /etc/shadow file complements /etc/passwd by storing encrypted password hashes and password policy fields such as the last change date, minimum and maximum age, and expiration warnings. While it references usernames, it does not contain core account information like UID, GID, home directory, or login shell. Because it holds sensitive hash data, it is restricted to root access, unlike the publicly readable /etc/passwd.
- ✗
/proc/cpuinfo
Why it's wrong here
The /proc filesystem is a virtual, in-memory pseudo-filesystem reflecting the current kernel state; /proc/cpuinfo specifically dumps CPU details such as vendor ID, model name, clock speed, cache size, and processor flags. It holds no user account data whatsoever. Its content changes at runtime and is populated by the kernel, making it useful for hardware identification but useless for account enumeration.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.