Courseiva
Advanced Password Attacks →mediumMultiple Choice

GPEN Advanced Password Attacks Practice Question

Which file in a Windows system is required, along with the NTDS.dit file, to decrypt cached credentials stored in the database?

⚠ Common exam trap

Candidates often suggest the SAM file is required. While the SAM file is used for local credential extraction, the SYSTEM hive is specifically required to decrypt the NTDS.dit database for domain-level credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYSTEM hive

The NTDS.dit file is the primary database for Active Directory, but it is encrypted. The encryption key, known as the boot key, is stored in the SYSTEM registry hive. Without access to the SYSTEM hive, the NTDS.dit file is useless for offline credential extraction. This relationship underscores the need for testers to obtain both files during a post-exploitation phase to achieve successful credential recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SAM hive

    Why it's wrong here

    The SAM hive contains local account hashes for a standalone system. It is not used for decrypting the NTDS.dit file, which stores domain-level objects. While the SAM is a valuable target for local privilege escalation, it plays no role in the decryption of domain-wide Active Directory credentials.

  • ✗

    SOFTWARE hive

    Why it's wrong here

    The SOFTWARE hive contains system-wide configuration data and installed application settings. It does not store the cryptographic keys required for decrypting the Active Directory database. It is often collected during forensic investigations but provides no assistance in the specific task of cracking domain-level NTDS.dit data.

  • ✓

    SYSTEM hive

    Why this is correct

    The SYSTEM hive contains the Boot Key (also known as the Syskey). This key is used to encrypt the database of Active Directory, NTDS.dit. Without this specific key, the hashes within the NTDS.dit file remain unreadable, making it impossible to perform any meaningful offline analysis of domain credentials.

  • ✗

    SECURITY hive

    Why it's wrong here

    The SECURITY hive stores local security policy information and some cached domain credentials. While it is an important target for extracting LSA secrets, it does not contain the master key required to decrypt the NTDS.dit database. It is technically distinct from the SYSTEM hive containing the boot key.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.