GCFA Windows Artifact Analysis Practice Question
When analyzing the Windows Registry, what is the primary purpose of the 'SAM' hive?
⚠ Common exam trap
Candidates often confuse the SAM hive with the SYSTEM hive or security logs, failing to identify the SAM as the specific location for local user authentication data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It contains local user account data and password hashes.
The SAM (Security Accounts Manager) hive contains local user account information, including password hashes and group memberships. It is a critical target during forensic analysis for identifying user accounts, password history, and potential privilege escalation attempts. By extracting these hashes, analysts can perform offline cracking to reveal passwords, which is often necessary to understand the full extent of a compromised account's capability within the organization's network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It stores the system's network configuration and IP addresses.
Why it's wrong here
Network configuration is stored in the SYSTEM hive, specifically under the Tcpip configuration keys. Misattributing this to the SAM hive shows a misunderstanding of the Windows registry structure. An analyst searching the SAM hive for network settings will be unable to find the data required for network reconstruction.
- ✗
It tracks all executed application history.
Why it's wrong here
Application execution history is tracked in UserAssist, Prefetch, and Amcache. The SAM hive does not contain this information. Searching the SAM hive for program execution will yield nothing, and the analyst will fail to build a timeline of the attacker's activity on the victim system.
- ✓
It contains local user account data and password hashes.
Why this is correct
The SAM hive is the repository for local user accounts. It stores account names, group membership, and password hashes. For forensic examiners, this is the primary source for identifying users on the system and potentially cracking passwords to determine the level of access an attacker gained.
- ✗
It holds the logs for all system boot events.
Why it's wrong here
System boot logs are stored in the System event logs. The registry SAM hive has nothing to do with boot event logging. Looking here will result in missing the boot timeline, which is vital for identifying when an attacker performed specific actions relative to the system's power states.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.