Which registry files can PRTK target for encrypted information or passwords?

Prepare for your FTK AccessData Certified Examiner (ACE) Test. Use flashcards, and multiple choice questions with explanations. Get ready for your certification exam!

The correct focus for targeting encrypted information or passwords using PRTK (Password Recovery Tool Kit) is on the SAM (Security Account Manager), SECURITY, and NTUSER.DAT registry files.

The SAM file contains user account information and stores hashed passwords for local user accounts. This file is crucial for recovering passwords as it holds a comprehensive directory of user accounts on the machine. The SECURITY file complements this by containing security policy information and other critical security settings, further aiding in the extraction of necessary credentials. NTUSER.DAT is specific to each user profile and contains user-specific settings, including encrypted passwords for certain applications.

While the SAM is a common factor across various choices, the inclusion of the SECURITY file alongside NTUSER.DAT in this answer provides a holistic approach, ensuring a thorough investigation of user authentication and access credentials. Other combinations listed do not include the SECURITY file, which is essential for PRTK's capability to uncover encrypted information effectively. Thus, option B stands out as it captures all the relevant files needed for successful password recovery and analysis.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy