Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

In Linux forensics, which file contains user account information including the user ID, group ID, home directory, and default shell?

⚠ Common exam trap

EC-CHFI often tests the distinction between /etc/passwd and /etc/shadow, trapping candidates who confuse the password storage location with the account information file, leading them to incorrectly select /etc/shadow because they associate it with user accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/etc/passwd

The /etc/passwd file is the standard Linux user database that stores essential account details, including the username, user ID (UID), group ID (GID), home directory path, and default shell. Each line in this file corresponds to a user account and uses a colon-delimited format (e.g., username:x:UID:GID:comment:home:shell). This file is world-readable because it does not contain passwords (which are stored in /etc/shadow), making it the correct source for the information listed in the question.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    /etc/passwd

    Why this is correct

    The /etc/passwd file is the traditional system account database in Linux, containing one colon-delimited entry per user account. Each line includes the username, a password placeholder (usually x), user ID, group ID, GECOS description, home directory, and default login shell. This file is the authoritative source for identifying which accounts exist on a system during forensic analysis. Password hashes themselves are stored separately in /etc/shadow, not here.

  • ✗

    /var/log/auth.log

    Why it's wrong here

    /var/log/auth.log is a system logging file that records authentication-related events such as successful and failed logins, sudo command executions, and SSH sessions. It does not define user accounts; rather, it provides a historical trail of when and how accounts were used. A forensic examiner might examine this file to reconstruct user activity, but the actual user account details like UID and home directory come from /etc/passwd.

  • ✗

    /etc/shadow

    Why it's wrong here

    The /etc/shadow file complements /etc/passwd by storing encrypted password hashes and password policy fields such as the last change date, minimum and maximum age, and expiration warnings. While it references usernames, it does not contain core account information like UID, GID, home directory, or login shell. Because it holds sensitive hash data, it is restricted to root access, unlike the publicly readable /etc/passwd.

  • ✗

    /proc/cpuinfo

    Why it's wrong here

    The /proc filesystem is a virtual, in-memory pseudo-filesystem reflecting the current kernel state; /proc/cpuinfo specifically dumps CPU details such as vendor ID, model name, clock speed, cache size, and processor flags. It holds no user account data whatsoever. Its content changes at runtime and is populated by the kernel, making it useful for hardware identification but useless for account enumeration.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.