GSEC Windows Forensics Practice Question
Exhibit
C:\Windows\System32\config\SOFTWARE Key: Microsoft\Windows NT\CurrentVersion\ProfileList Value: ProfileImagePath = C:\Users\Admin
Refer to the exhibit. An investigator identifies this registry key. What is the primary purpose of this information in a forensic investigation?
⚠ Common exam trap
Candidates often confuse the ProfileList registry key with general system configuration keys. They fail to recognize that this specific key is the primary link between user SIDs and profile paths.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It maps Security Identifiers (SIDs) to user profile directories.
The ProfileList key maps SIDs to user profile paths. This is critical because an attacker may create a temporary or hidden account. By identifying the exact path to the user profile, the investigator knows where to look for user-specific artifacts like NTUSER.DAT, browser history, and temporary files. This mapping is the starting point for scoping user-level malicious activities and ensuring that no hidden accounts are overlooked during the investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It defines the system's default language settings.
Why it's wrong here
The ProfileList key is dedicated to profile management and SID-to-path resolution, not language or regional settings. Regional settings are typically located in the HKEY_CURRENT_USER hive or under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls, making this option technically incorrect regarding the function of the ProfileList key.
- ✓
It maps Security Identifiers (SIDs) to user profile directories.
Why this is correct
ProfileList is the authoritative source for locating where a user's profile resides on the disk. For an investigator, this is essential to verify account existence and identify the correct directory path for further analysis of user-specific artifacts that might contain evidence of attacker activity.
- ✗
It logs every application the user has executed.
Why it's wrong here
ProfileList only stores profile path locations and account SIDs. It does not contain execution logs. Execution history is stored in different artifacts like UserAssist, Shimcache, or Prefetch, which serve entirely different purposes and are located in different registry hives and file system structures.
- ✗
It lists all installed software on the system.
Why it's wrong here
The list of installed software is typically tracked under the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall key. The ProfileList key is strictly for user account profile management and path mapping, providing no insights into the software inventory of the local machine or remote network connections.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.