Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

In Windows registry forensics, which registry hive contains the SAM database storing local user account hashes?

⚠ Common exam trap

In CHFI, a common mistake is confusing HKLM\Security (stores cached domain credentials) with HKLM\SAM (stores local account hashes). Also, NTUSER.DAT only contains user-specific settings, not system-wide account data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKLM\Sam

The SAM (Security Account Manager) database, which stores local user account password hashes (LM and NTLM hashes), is mounted in the Windows registry under the HKLM\SAM hive. This hive is directly accessible only by the SYSTEM account for security reasons, and it contains the hashes in the SAM\SAM\Domains\Account\Users subkey. Option D is correct because HKLM\Sam is the exact registry path where the SAM database resides.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKLM\Security

    Why it's wrong here

    HKLM\Security is the registry hive for Local Security Authority (LSA) policy data, holding user-rights assignments, audit policy, and LSA secrets, not the password-hash database. Although cached domain credentials appear under HKLM\Security\Cache, forensic investigators must distinguish those cached domain entries from the local account hashes stored in SAM. Therefore selecting Security mistakes policy data for the SAM credential database.

  • ✗

    HKLM\System

    Why it's wrong here

    HKLM\System stores the system-wide configuration for booting Windows, including the current ControlSet, service and device-driver parameters, and hardware profiles. The SAM database is not a subkey of System, and user account hashes are never kept in that hive; this option incorrectly identifies a configuration hive as the location of credential material. System is relevant to artifacts like LastKnownGood and startup services, not to account hashes.

  • ✗

    NTUSER.DAT

    Why it's wrong here

    NTUSER.DAT is the per-user registry hive loaded as HKEY_CURRENT_USER, containing personal environment, desktop, application, and preferences for an individual profile. It does not contain the Security Accounts Manager database; user SID and account settings are in SAM, while NTUSER.DAT only reflects the settings for that logged-in user. So although NTUSER.DAT is useful for user activity forensics, it is not the local account hash store.

  • ✓

    HKLM\Sam

    Why this is correct

    HKLM\SAM is the loaded registry view of the Security Accounts Manager database, and it contains the local user account hashes under HKLM\SAM\SAM\Domains\Account\Users. Each user key is named by the account's relative identifier (RID), and the V value contains the LM/NTLM hash verifiers used by Windows to authenticate local accounts. This is how the operating system exposes the credential store in the registry, making SAM the correct forensic target.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.