CHFI OS and Network Forensics Practice Question
A Windows system's registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' contains a subkey with a serial number. What does this artifact indicate?
⚠ Common exam trap
EC-Council often tests the misconception that all USB devices (e.g., keyboards, printers) are logged under the same 'USBSTOR' key, but in reality, only mass storage devices appear there, while other USB classes have separate enumeration paths.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A USB storage device was attached
The registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' specifically enumerates USB mass storage devices (e.g., flash drives, external hard drives). The presence of a subkey with a serial number indicates that a USB storage device was attached and recognized by the Windows operating system, as the serial number uniquely identifies the device. This key is a primary artifact in USB forensics for tracking storage device connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A USB network adapter was attached
Why it's wrong here
USB network adapters (Ethernet or Wi-Fi dongles) are enumerated under the NET class GUID in HKLM\SYSTEM\CurrentControlSet\Enum, not under USBSTOR. USBSTOR exists exclusively for USB mass-storage devices (flash drives, external disks) that implement the USB Mass Storage Class (class code 08). Therefore, an artifact in USBSTOR indicates storage media attachment, not network hardware attachment.
- ✓
A USB storage device was attached
Why this is correct
The USBSTOR subkey in HKLM\SYSTEM\CurrentControlSet\Enum is populated when Windows enumerates a USB mass-storage device, such as a flash drive, external HDD, or card reader. It creates a subkey named like Disk&Ven_<vid>&Prod_<pid>&Rev_<rev>, and the key's LastWrite time can be used as forensic timeline evidence of the device's most recent connection to the system. This is why this key points directly to a USB storage device.
- ✗
A USB printer was attached
Why it's wrong here
USB printers do not appear in USBSTOR; they are enumerated either under the 'PRINT' class or as a USB interface class 07 device under HKLM\SYSTEM\CurrentControlSet\Enum\USB\VID_... using the printer interface descriptor. USBSTOR is reserved for storage devices with USB class code 08 (Mass Storage), so a printer lacks the required storage interface and cannot generate an entry there.
- ✗
A USB keyboard was attached
Why it's wrong here
A USB keyboard is a Human Interface Device (HID) and is enumerated under HKLM\SYSTEM\CurrentControlSet\Enum\HID, using a usage page of 0x01 and usage ID 0x06 for keyboards, or under the USB key with HID interface class 03. USBSTOR only records mass-storage devices, so a keyboard does not produce a USBSTOR key. Thus, observing USBSTOR entries cannot be used to infer keyboard attachment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.