CHFI OS and Network Forensics Practice Question
A forensic analyst is examining a Windows system for evidence of USB device usage. Which TWO registry locations are known to store USB device history?
⚠ Common exam trap
EC-Council often tests the distinction between system-wide (HKLM) and user-specific (HKCU) registry hives, and candidates mistakenly think only one location stores USB history, overlooking that both USBSTOR and MountPoints2 are valid and complementary sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Option A is correct because HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the primary registry key where Windows records USB mass storage devices that have been connected, storing device instance IDs, serial numbers, and vendor/product information used to prove USB storage usage. Option B is correct because HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 tracks per-user mounted volumes, including USB drives, by recording volume GUIDs and drive-letter mappings that correlate a device to a specific user account. Option C is incorrect because the Prefetch registry path does not exist as a USB history store; prefetch execution evidence resides in C:\Windows\Prefetch as .pf files, not in that registry location. Option D is incorrect because HKCU\...\Run is an autostart persistence key for programs launched at logon, not a record of USB device connections. Option E is incorrect because HKLM\SAM\...\Users stores local account and credential-related data (such as RID-based user records and password hashes), not USB device history.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Why this is correct
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the Windows Plug and Play device enumeration tree for USB mass storage devices, recording every device instance that has ever been connected to the system. Each subkey is named with the device's vendor, product, and unique serial number, and it persists even after the device is unplugged, making it a critical artifact for proving a specific USB drive was attached. Forensic examiners use this key to identify not only the make/model but also the serial number and, when correlated with SetupAPI logs, the first/last connection times.
- ✓
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
Why this is correct
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 stores per-user mappings of volume mount points, including subkeys like {GUID}\Volume{...} that correspond to the volume serial number of a connected USB drive. It also retains cached drive labels and other shell metadata, allowing an analyst to associate a particular user profile with a removable device. Unlike USBSTOR, this key does not list hardware vendor IDs or serial numbers; instead it provides user-level corroborating data, such as the drive letter and friendly name, when a user actually browsed the drive.
- ✗
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Prefetch
Why it's wrong here
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Prefetch contains configuration values for the Prefetcher, not a list of USB devices. The Prefetch system actually stores .pf files in C:\Windows\Prefetch that map applications to the files they load, and while those files can indirectly show that a program was executed from a connected USB drive, this registry key itself only holds settings like EnablePrefetcher. Therefore, this key is not a direct source for identifying USB storage devices and is a common misconception in USB forensic examinations.
- ✗
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
HKCU\Software\Microsoft\Windows\CurrentVersion\Run is an autorun registry key used to launch programs each time the user logs on, so it contains command lines for executables, not any record of device connections. Even though malware delivered via USB could create a persistence entry here, the key merely indicates that a program is configured to run; it does not demonstrate that a USB drive was attached or which device was involved. This makes it irrelevant for USB device identification, though it may be relevant in a malware investigation.
- ✗
HKLM\SAM\SAM\Domains\Account\Users
Why it's wrong here
HKLM\SAM\SAM\Domains\Account\Users is the Security Accounts Manager database that stores local user account information, including the NT and LM password hashes in the V values of each user key. It does not contain any hardware, device, or USB connection records, so it cannot be used to determine whether a USB storage device was ever connected. Forensic analysts might use this key for account enumeration or credential recovery, but it is not a USB artifact and is often mistakenly included in a list of forensically meaningful locations for device tracking.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.