On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

On an Active Directory network using NTLM authentication, where on the domain controllers are the passwords stored?

Explanation:
Windows stores password hashes in a secure local database called the Security Account Manager (SAM). On a domain controller, SAM is the component that holds the credential hashes Windows uses to validate logon attempts, including those using NTLM. When a user attempts to log in (and NTLM is involved), the system compares the presented password hash to the one stored in SAM and grants access if they match. This is why SAM is described as the storage location for passwords on domain controllers in this context. (Note: in an Active Directory setup, domain password data is ultimately managed by the Active Directory database, but the SAM on the domain controller is the direct repository involved in the local NTLM authentication process.)

Windows stores password hashes in a secure local database called the Security Account Manager (SAM). On a domain controller, SAM is the component that holds the credential hashes Windows uses to validate logon attempts, including those using NTLM. When a user attempts to log in (and NTLM is involved), the system compares the presented password hash to the one stored in SAM and grants access if they match. This is why SAM is described as the storage location for passwords on domain controllers in this context. (Note: in an Active Directory setup, domain password data is ultimately managed by the Active Directory database, but the SAM on the domain controller is the direct repository involved in the local NTLM authentication process.)

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy