Courseiva
Windows Forensics →hardMultiple Choice

GSEC Windows Forensics Practice Question

An examiner is analyzing a Windows 10 endpoint and finds that the user account was deleted before acquisition, but the examiner still needs to determine which files that user recently opened from a network share. The user's profile folder was also removed. Which artifact is most likely to retain this information?

⚠ Common exam trap

The trap here is assuming that user-scoped artifacts such as NTUSER.DAT and UsrClass.dat remain available after the profile is deleted, when in fact they are removed with the profile folder.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Security event log's object access auditing entries in the Security.evtx file

Object access auditing, when enabled, writes file access events to the Security event log, which is system-scoped and stored under winevt\Logs, so it survives deletion of the user account and profile. Per-user hives such as NTUSER.DAT and UsrClass.dat are removed with the profile, and SRUM records resource usage rather than file opens.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Security event log's object access auditing entries in the Security.evtx file

    Why this is correct

    If object access auditing was enabled, the Security event log records file access events, including the account name, the object path, and the share accessed. Because the log is stored in C:\Windows\System32\winevt\Logs and is system-scoped, it survives deletion of the user profile and account. It is the most likely remaining source for the user's recent file opens from a network share.

  • ✗

    The SRUM database's Application Resource Usage table

    Why it's wrong here

    SRUM records per-application resource consumption such as CPU time and bytes sent and received, keyed by application and user SID over time. It does not log individual file open events or network share paths. Even if the user SID is still present, SRUM cannot identify which specific files the user opened from a share.

  • ✗

    The NTUSER.DAT hive from the deleted user's profile folder

    Why it's wrong here

    NTUSER.DAT is the per-user registry hive that stores RecentDocs, UserAssist, and other user-scoped artifacts. When the profile folder is removed, that hive is deleted along with it, so its contents are no longer available. Relying on it here is not viable because the scenario explicitly states the profile folder was removed.

  • ✗

    The UsrClass.dat hive from the deleted user's profile folder

    Why it's wrong here

    UsrClass.dat is another per-user hive, stored under the user's AppData\Local\Microsoft\Windows folder, and holds shellbags and other user-specific COM and shell data. Like NTUSER.DAT, it resides in the profile folder and is removed when the profile is deleted. It therefore cannot answer the question in this scenario.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.