CHFI OS and Network Forensics Practice Question
In Windows registry forensics, which registry hive contains the SAM database storing local user account hashes?
⚠ Common exam trap
In CHFI, a common mistake is confusing HKLM\Security (stores cached domain credentials) with HKLM\SAM (stores local account hashes). Also, NTUSER.DAT only contains user-specific settings, not system-wide account data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKLM\Sam
The SAM (Security Account Manager) database, which stores local user account password hashes (LM and NTLM hashes), is mounted in the Windows registry under the HKLM\SAM hive. This hive is directly accessible only by the SYSTEM account for security reasons, and it contains the hashes in the SAM\SAM\Domains\Account\Users subkey. Option D is correct because HKLM\Sam is the exact registry path where the SAM database resides.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HKLM\Security
Why it's wrong here
HKLM\Security is the registry hive for Local Security Authority (LSA) policy data, holding user-rights assignments, audit policy, and LSA secrets, not the password-hash database. Although cached domain credentials appear under HKLM\Security\Cache, forensic investigators must distinguish those cached domain entries from the local account hashes stored in SAM. Therefore selecting Security mistakes policy data for the SAM credential database.
- ✗
HKLM\System
Why it's wrong here
HKLM\System stores the system-wide configuration for booting Windows, including the current ControlSet, service and device-driver parameters, and hardware profiles. The SAM database is not a subkey of System, and user account hashes are never kept in that hive; this option incorrectly identifies a configuration hive as the location of credential material. System is relevant to artifacts like LastKnownGood and startup services, not to account hashes.
- ✗
NTUSER.DAT
Why it's wrong here
NTUSER.DAT is the per-user registry hive loaded as HKEY_CURRENT_USER, containing personal environment, desktop, application, and preferences for an individual profile. It does not contain the Security Accounts Manager database; user SID and account settings are in SAM, while NTUSER.DAT only reflects the settings for that logged-in user. So although NTUSER.DAT is useful for user activity forensics, it is not the local account hash store.
- ✓
HKLM\Sam
Why this is correct
HKLM\SAM is the loaded registry view of the Security Accounts Manager database, and it contains the local user account hashes under HKLM\SAM\SAM\Domains\Account\Users. Each user key is named by the account's relative identifier (RID), and the V value contains the LM/NTLM hash verifiers used by Windows to authenticate local accounts. This is how the operating system exposes the credential store in the registry, making SAM the correct forensic target.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.