Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic analyst is examining a Windows 10 system for evidence of USB device usage. Which registry hive and key path should she check to find a list of USB devices that have been connected to the system?

⚠ Common exam trap

The EC-Council CHFI exam often tests the misconception that USB device history is stored in the SAM hive or in user-specific NTUSER.DAT shell bags, when in fact the definitive list resides in the SYSTEM hive's USBSTOR enumeration key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR

The USBSTOR key under HKLM\SYSTEM\CurrentControlSet\Enum stores the device instance IDs and class GUIDs for every USB mass storage device that has ever been connected to the system. This is the primary forensic artifact for enumerating historical USB device attachments on Windows 10.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKLM\SAM\SAM\Domains\Account\Users

    Why it's wrong here

    The SAM hive's Domains\Account\Users subtree stores local account definitions, RID mappings and password hashes, not peripheral history. It tempts because SAM is a well-known forensic hive for user accounts. USB device evidence sits in HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR instead.

  • ✓

    HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR

    Why this is correct

    USBSTOR enumerates storage-class USB devices, recording vendor, product and serial number for each device ever attached. This key sits under the SYSTEM hive's CurrentControlSet, making it the definitive artefact for proving historical USB mass-storage connections on Windows 10.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Why it's wrong here

    The Run key lists programs configured to launch at user logon; it holds no USB device history. Investigators are tempted because Run keys are a familiar persistence location. USB artefacts instead reside under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR, which records connected storage devices.

  • ✗

    NTUSER.DAT\Software\Microsoft\Windows\ShellNoRoam\BagMRU

    Why it's wrong here

    ShellNoRoam\BagMRU stores per-user shell folder view settings, including window positions and sort orders, not device connection records. It tempts because it is a per-user registry location tied to Explorer activity. USB enumeration data lives in the SYSTEM hive under Enum\USBSTOR.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.