nerdexam
Cisco

300-215 · Question #25

An organization uses a Windows 7 workstation for access tracking in one of their physical data centers on which a guard documents entrance/exit activities of all personnel. A server shut down…

The correct answer is B. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\ProfileList. This location stores information about each user profile on the machine, including login activity and the LastWrite time for forensic tracking.

Submitted by yaw92· Mar 6, 2026Forensics Techniques

Question

An organization uses a Windows 7 workstation for access tracking in one of their physical data centers on which a guard documents entrance/exit activities of all personnel. A server shut down unexpectedly in this data center, and a security specialist is analyzing the case. Initial checks show that the previous two days of entrance/exit logs are missing, and the guard is confident that the logs were entered on the workstation. Where should the security specialist look next to continue investigating this case?

Options

  • AHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon
  • BHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\ProfileList
  • CHKEY_CURRENT_USER\Software\Classes\Winlog
  • DHKEY_LOCAL_MACHINES\SOFTWARE\Microsoft\WindowsNT\CurrentUser

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    76% (22)
  • C
    14% (4)
  • D
    3% (1)

Explanation

This location stores information about each user profile on the machine, including login activity and the LastWrite time for forensic tracking.

Topics

#Windows forensics#registry analysis#user profiles#log investigation

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice