CHFI OS and Network Forensics Practice Question
Which Windows Registry hive contains user-specific configuration such as MRU lists and UserAssist artifacts?
⚠ Common exam trap
The EC-Council CHFI often tests the misconception that HKLM\System or SYSTEM contains user-specific data, but these hives are system-wide and do not store per-user artifacts like MRU lists or UserAssist entries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTUSER.DAT
The NTUSER.DAT file is the registry hive that stores per-user configuration settings, including MRU (Most Recently Used) lists and UserAssist artifacts. When a user logs into a Windows system, this hive is loaded into HKEY_CURRENT_USER (HKCU), making it the primary source for user-specific forensic artifacts such as executed program traces and file access history.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NTUSER.DAT
Why this is correct
NTUSER.DAT is the per-user registry hive that Windows loads into HKEY_CURRENT_USER when a user logs on. It contains user-specific configuration such as desktop settings, environment variables, application preferences, and network drive mappings, stored in the user's profile directory. This makes it the only hive among the options that directly holds individual user settings.
- ✗
HKLM\SAM
Why it's wrong here
The SAM (Security Accounts Manager) hive under HKEY_LOCAL_MACHINE maintains the local account database, including user account names, password hashes (in the V value), and account groups. It governs authentication for the local machine rather than storing desktop, environmental, or application-level user preferences. Therefore, SAM is not the hive for user-specific configuration.
- ✗
SYSTEM
Why it's wrong here
The SYSTEM registry hive is a machine-level database file (commonly C:\Windows\System32\config\SYSTEM) that is mounted as HKLM\SYSTEM. It holds system-wide boot parameters, device drivers, kernel configuration, and service startup information for the entire Windows installation. Because it is shared by all users and contains no per-user profile data, it does not meet the definition of a user-specific registry hive.
- ✗
HKLM\System
Why it's wrong here
HKLM\SYSTEM is the in-memory registry key that exposes the SYSTEM hive under HKEY_LOCAL_MACHINE, and it represents global machine settings rather than a single user's environment. Administrators can view it to inspect driver and service configurations, but any modifications affect the whole system and all users concurrently. This global scope disqualifies it from being the hive containing per-user configuration.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.