Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

Which Windows Registry hive is primarily used to store user-specific application settings and recently accessed files?

⚠ Common exam trap

EC-Council often tests the misconception that HKCU is a separate hive file, when in fact it is a dynamic view of NTUSER.DAT loaded from the user's profile directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NTUSER.DAT

NTUSER.DAT is the correct answer because it is the registry hive file that stores per-user settings, including application configurations and recently accessed files (e.g., MRU lists). When a user logs on, Windows loads NTUSER.DAT into HKEY_CURRENT_USER (HKCU), making it the primary repository for user-specific data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKU\.DEFAULT

    Why it's wrong here

    HKU\.DEFAULT is the registry hive loaded for the LocalSystem account, not for an interactive end user. It contains default environment settings and user profile data for the system-level service account, and it is not the primary hive consulted when a normal user logs on. Forensic examiners should not mistake it for the root of per-user preferences; its contents are typically sparse and system-oriented.

  • ✗

    HKLM\SYSTEM

    Why it's wrong here

    HKLM\SYSTEM holds computer-wide configuration data such as device drivers, services, startup parameters, and control sets (e.g., Select, CurrentControlSet). It does not contain per-user settings, user profiles, or user recent items; those are kept in hives like NTUSER.DAT or SOFTWARE. In investigations, SYSTEM is useful for persistence analysis, but it is not the hive for storing a given user's preferences.

  • ✗

    HKLM\SAM

    Why it's wrong here

    HKLM\SAM, the Security Accounts Manager hive, stores local user and group account metadata, including the password hashes (e.g., LM/NTLM hashes) and SIDs for accounts on the machine. It is not a repository of user settings, desktop configuration, or application preferences. Moreover, SAM is normally locked while Windows is running, and its content is purpose-built for authentication rather than user profile state.

  • ✓

    NTUSER.DAT

    Why this is correct

    NTUSER.DAT is the registry hive loaded into HKCU when a user logs on, and it contains that user's personal settings, application preferences, environment variables, desktop appearance, and recent documents. It is stored in the user's profile directory (e.g., C:\Users\Username\NTUSER.DAT) and is a key artifact for forensic analysis of user activity and configuration. The question's 'user' is best answered by NTUSER.DAT because HKCU itself is not a file, but NTUSER.DAT is the physical hive that backs it.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.