GSEC Windows Forensics Practice Question
An examiner is analyzing a Windows 10 endpoint and finds that the user account was deleted before acquisition, but the examiner still needs to determine which files that user recently opened from a network share. The user's profile folder was also removed. Which artifact is most likely to retain this information?
⚠ Common exam trap
The trap here is assuming that user-scoped artifacts such as NTUSER.DAT and UsrClass.dat remain available after the profile is deleted, when in fact they are removed with the profile folder.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Security event log's object access auditing entries in the Security.evtx file
Object access auditing, when enabled, writes file access events to the Security event log, which is system-scoped and stored under winevt\Logs, so it survives deletion of the user account and profile. Per-user hives such as NTUSER.DAT and UsrClass.dat are removed with the profile, and SRUM records resource usage rather than file opens.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Security event log's object access auditing entries in the Security.evtx file
Why this is correct
If object access auditing was enabled, the Security event log records file access events, including the account name, the object path, and the share accessed. Because the log is stored in C:\Windows\System32\winevt\Logs and is system-scoped, it survives deletion of the user profile and account. It is the most likely remaining source for the user's recent file opens from a network share.
- ✗
The SRUM database's Application Resource Usage table
Why it's wrong here
SRUM records per-application resource consumption such as CPU time and bytes sent and received, keyed by application and user SID over time. It does not log individual file open events or network share paths. Even if the user SID is still present, SRUM cannot identify which specific files the user opened from a share.
- ✗
The NTUSER.DAT hive from the deleted user's profile folder
Why it's wrong here
NTUSER.DAT is the per-user registry hive that stores RecentDocs, UserAssist, and other user-scoped artifacts. When the profile folder is removed, that hive is deleted along with it, so its contents are no longer available. Relying on it here is not viable because the scenario explicitly states the profile folder was removed.
- ✗
The UsrClass.dat hive from the deleted user's profile folder
Why it's wrong here
UsrClass.dat is another per-user hive, stored under the user's AppData\Local\Microsoft\Windows folder, and holds shellbags and other user-specific COM and shell data. Like NTUSER.DAT, it resides in the profile folder and is removed when the profile is deleted. It therefore cannot answer the question in this scenario.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.