Windows Registry Hive Flashcards

1
Q

Name the 2 type of hives.

A
  • System Hive
  • User Hive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a hive

A

A binary file that contains a registry tree including:
- keys
- subkeys
- values

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Where do System and User hive relates to?

A
  • System –> HKLM (HKEY_LOCAL_MACHINE)
  • User –> HKU (HKEY_USERS)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is HKEY?

A

It stands for Handle to Key or HK.
The logical section, Root keys beginning with it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the supporting file for HKLM\SAM ?

A

sam, sam.log, sam.log1, sam.log2, blf.
(SAM = Security Account Manager)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the supporting file for HKLM\SECURITY ?

A

security, security.log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is supporting file for HKLM\SOFTWARE ?

A

software, software.log, software.log1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is supporting file for HKLM\SYSTEM ?

A

system, system.log, system.log1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the supporting file for HK_CURRENT_CONFIG ?

A

system, system.log, system.log1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where can the “system” hive files be found?

A

C:\Windows\System32\config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Where can the “user” hive files be found?

A

HKU\.DEFAULT (C:\Windows\System32\config)
HKU\SID (C:\Users\john\NTUSER.DAT)
HKU\SID_CLASSES (C:\Users\john\AppData\Local\Microsoft\Windows\UsrClass.DAT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly