CHFI OS and Network Forensics Practice Question
In Linux, which file contains hashed user passwords?
⚠ Common exam trap
EC-Council often tests the misconception that /etc/passwd still contains password hashes, leading candidates to choose option C, but modern Linux systems have moved hashes to /etc/shadow for security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/shadow
The /etc/shadow file stores hashed user passwords along with password aging information, and is readable only by root to enhance security. In contrast, /etc/passwd contains user account information but stores only a placeholder (usually 'x' or '*') for the password hash, not the hash itself. This separation is a standard Linux security mechanism to prevent unauthorized access to password hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/etc/gshadow
Why it's wrong here
The /etc/gshadow file is the shadow file for group passwords, not user passwords. It stores an encrypted group password hash, the group's administrator list, and member list for privileged group operations. Since it exists to secure group-level authentication (e.g., newgrp), it has exactly zero fields pertaining to individual user login credentials. Therefore, hashed user passwords are never in this file.
- ✗
/etc/group
Why it's wrong here
/etc/group is a world-readable database that maps group names to GIDs and lists which user accounts are members of each group. It contains no authentication material whatsoever; its only password-related column is a placeholder 'x' if a group password exists in /etc/gshadow. User login password hashes are intentionally kept out of this file because it is readable by every user and contains only membership metadata.
- ✗
/etc/passwd
Why it's wrong here
Historically, /etc/passwd held encrypted user passwords, but modern systems with shadow suites replace the password field with a mere 'x' placeholder. As a world-readable file, /etc/passwd stores user account attributes (UID, GID, GECOS, home directory, shell) and must not expose hashes. The actual hashed user passwords are relocated to /etc/shadow, which has restricted permissions, so /etc/passwd itself is only a red herring.
- ✓
/etc/shadow
Why this is correct
/etc/shadow is the authoritative shadow password database that contains each user's hashed password and related aging metadata. It is typically readable only by root and the shadow group (mode 640 root:shadow) precisely because it holds credential verifiers. Fields include login name, password hash (often with $id$salt$hash format), last change, minimum/maximum age, warning, inactivity, and expiration. Thus the answer to the question is /etc/shadow.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.