Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

Which Windows Registry hive contains user-specific configuration such as MRU lists and UserAssist artifacts?

⚠ Common exam trap

The EC-Council CHFI often tests the misconception that HKLM\System or SYSTEM contains user-specific data, but these hives are system-wide and do not store per-user artifacts like MRU lists or UserAssist entries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NTUSER.DAT

The NTUSER.DAT file is the registry hive that stores per-user configuration settings, including MRU (Most Recently Used) lists and UserAssist artifacts. When a user logs into a Windows system, this hive is loaded into HKEY_CURRENT_USER (HKCU), making it the primary source for user-specific forensic artifacts such as executed program traces and file access history.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NTUSER.DAT

    Why this is correct

    NTUSER.DAT is the per-user registry hive that Windows loads into HKEY_CURRENT_USER when a user logs on. It contains user-specific configuration such as desktop settings, environment variables, application preferences, and network drive mappings, stored in the user's profile directory. This makes it the only hive among the options that directly holds individual user settings.

  • ✗

    HKLM\SAM

    Why it's wrong here

    The SAM (Security Accounts Manager) hive under HKEY_LOCAL_MACHINE maintains the local account database, including user account names, password hashes (in the V value), and account groups. It governs authentication for the local machine rather than storing desktop, environmental, or application-level user preferences. Therefore, SAM is not the hive for user-specific configuration.

  • ✗

    SYSTEM

    Why it's wrong here

    The SYSTEM registry hive is a machine-level database file (commonly C:\Windows\System32\config\SYSTEM) that is mounted as HKLM\SYSTEM. It holds system-wide boot parameters, device drivers, kernel configuration, and service startup information for the entire Windows installation. Because it is shared by all users and contains no per-user profile data, it does not meet the definition of a user-specific registry hive.

  • ✗

    HKLM\System

    Why it's wrong here

    HKLM\SYSTEM is the in-memory registry key that exposes the SYSTEM hive under HKEY_LOCAL_MACHINE, and it represents global machine settings rather than a single user's environment. Administrators can view it to inspect driver and service configurations, but any modifications affect the whole system and all users concurrently. This global scope disqualifies it from being the hive containing per-user configuration.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.