GPEN Advanced Password Attacks Practice Question
Which file in a Windows system is required, along with the NTDS.dit file, to decrypt cached credentials stored in the database?
⚠ Common exam trap
Candidates often suggest the SAM file is required. While the SAM file is used for local credential extraction, the SYSTEM hive is specifically required to decrypt the NTDS.dit database for domain-level credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYSTEM hive
The NTDS.dit file is the primary database for Active Directory, but it is encrypted. The encryption key, known as the boot key, is stored in the SYSTEM registry hive. Without access to the SYSTEM hive, the NTDS.dit file is useless for offline credential extraction. This relationship underscores the need for testers to obtain both files during a post-exploitation phase to achieve successful credential recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SAM hive
Why it's wrong here
The SAM hive contains local account hashes for a standalone system. It is not used for decrypting the NTDS.dit file, which stores domain-level objects. While the SAM is a valuable target for local privilege escalation, it plays no role in the decryption of domain-wide Active Directory credentials.
- ✗
SOFTWARE hive
Why it's wrong here
The SOFTWARE hive contains system-wide configuration data and installed application settings. It does not store the cryptographic keys required for decrypting the Active Directory database. It is often collected during forensic investigations but provides no assistance in the specific task of cracking domain-level NTDS.dit data.
- ✓
SYSTEM hive
Why this is correct
The SYSTEM hive contains the Boot Key (also known as the Syskey). This key is used to encrypt the database of Active Directory, NTDS.dit. Without this specific key, the hashes within the NTDS.dit file remain unreadable, making it impossible to perform any meaningful offline analysis of domain credentials.
- ✗
SECURITY hive
Why it's wrong here
The SECURITY hive stores local security policy information and some cached domain credentials. While it is an important target for extracting LSA secrets, it does not contain the master key required to decrypt the NTDS.dit database. It is technically distinct from the SYSTEM hive containing the boot key.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.