CHFI OS and Network Forensics Practice Question
Which Windows Registry hive is primarily used to store user-specific application settings and recently accessed files?
⚠ Common exam trap
EC-Council often tests the misconception that HKCU is a separate hive file, when in fact it is a dynamic view of NTUSER.DAT loaded from the user's profile directory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NTUSER.DAT
NTUSER.DAT is the correct answer because it is the registry hive file that stores per-user settings, including application configurations and recently accessed files (e.g., MRU lists). When a user logs on, Windows loads NTUSER.DAT into HKEY_CURRENT_USER (HKCU), making it the primary repository for user-specific data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HKU\.DEFAULT
Why it's wrong here
HKU\.DEFAULT is the registry hive loaded for the LocalSystem account, not for an interactive end user. It contains default environment settings and user profile data for the system-level service account, and it is not the primary hive consulted when a normal user logs on. Forensic examiners should not mistake it for the root of per-user preferences; its contents are typically sparse and system-oriented.
- ✗
HKLM\SYSTEM
Why it's wrong here
HKLM\SYSTEM holds computer-wide configuration data such as device drivers, services, startup parameters, and control sets (e.g., Select, CurrentControlSet). It does not contain per-user settings, user profiles, or user recent items; those are kept in hives like NTUSER.DAT or SOFTWARE. In investigations, SYSTEM is useful for persistence analysis, but it is not the hive for storing a given user's preferences.
- ✗
HKLM\SAM
Why it's wrong here
HKLM\SAM, the Security Accounts Manager hive, stores local user and group account metadata, including the password hashes (e.g., LM/NTLM hashes) and SIDs for accounts on the machine. It is not a repository of user settings, desktop configuration, or application preferences. Moreover, SAM is normally locked while Windows is running, and its content is purpose-built for authentication rather than user profile state.
- ✓
NTUSER.DAT
Why this is correct
NTUSER.DAT is the registry hive loaded into HKCU when a user logs on, and it contains that user's personal settings, application preferences, environment variables, desktop appearance, and recent documents. It is stored in the user's profile directory (e.g., C:\Users\Username\NTUSER.DAT) and is a key artifact for forensic analysis of user activity and configuration. The question's 'user' is best answered by NTUSER.DAT because HKCU itself is not a file, but NTUSER.DAT is the physical hive that backs it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.