Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 171 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 171
Topic #: 1
[All 312-49v10 Questions]

What is kept in the following directory? HKLM\SECURITY\Policy\Secrets

  • A. Cached password hashes for the past 20 users
  • B. Service account passwords in plain text
  • C. IAS account names and passwords
  • D. Local store PKI Kerberos certificates
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MicrosoftMaster2023
6 months, 1 week ago
There is no plain text pw in that hive, so remains cached.
upvoted 1 times
...
Elb
6 months, 3 weeks ago
B > credentials for service accounts are stored in the local registry, as what's called "LSA Secrets" in the registry key HKEY_LOCAL_MACHINE/Security/Policy/Secrets. Because the service needs to read the actual password to login as the service account, that password is in the registry in clear-text.
upvoted 1 times
...
Elb
6 months, 3 weeks ago
Selected Answer: B
B < https://attack.mitre.org/techniques/T1003/004/ Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts.[1][2][3] LSA secrets are stored in the registry at HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets. LSA secrets can also be dumped from memory.[
upvoted 1 times
...
Elb
1 year, 4 months ago
C: Thinking that might have an intentional typo, so might the answer be LSA instead of IAS...
upvoted 2 times
...
BarryMacockener
2 years ago
This answer is incorrect, but I'm not sure what the correct answer is. As vcloudpmp stated, LSA secrets are stored in this key, and they do include service account passwords, but they are NOT in plain text. Everything is encrypted. The answer choices to this question may not be accurate.
upvoted 1 times
...
vcloudpmp
2 years, 8 months ago
The Local Security Authority (LSA) in Windows is designed to manage a systems security policy, auditing, logging users on to the system, and storing private data such as service account passwords. The LSA secrets are stored under the HKLM:\Security\Policy\Secrets key. This key contains additional subkeys that store encrypted secrets. The HKLM:\Security\Policy\Secrets key is not accessible from regedit or other tools by default, but we can access it by running the Enable-TSDuplicateToken function described in yesterday’s blog, Use PowerShell to Duplicate Process Tokens via P/Invoke. The secrets are available in the 32-bit registry. Step one is to start an elevated 32-bit Windows PowerShell prompt.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...