On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?

Enhance your knowledge as a Computer Hacking Forensic Investigator with the CHFI v11 Test. Use flashcards and multiple-choice questions, complete with hints and detailed explanations, to prepare effectively and ace your exam!

Multiple Choice

On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?

Explanation:
Windows stores password hashes in a secure local database called the Security Account Manager (SAM). On a domain controller, SAM is the component that holds the credential hashes Windows uses to validate logon attempts, including those using NTLM. When a user attempts to log in (and NTLM is involved), the system compares the presented password hash to the one stored in SAM and grants access if they match. This is why SAM is described as the storage location for passwords on domain controllers in this context. (Note: in an Active Directory setup, domain password data is ultimately managed by the Active Directory database, but the SAM on the domain controller is the direct repository involved in the local NTLM authentication process.)

Windows stores password hashes in a secure local database called the Security Account Manager (SAM). On a domain controller, SAM is the component that holds the credential hashes Windows uses to validate logon attempts, including those using NTLM. When a user attempts to log in (and NTLM is involved), the system compares the presented password hash to the one stored in SAM and grants access if they match. This is why SAM is described as the storage location for passwords on domain controllers in this context. (Note: in an Active Directory setup, domain password data is ultimately managed by the Active Directory database, but the SAM on the domain controller is the direct repository involved in the local NTLM authentication process.)

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy