Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A Windows system's registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' contains a subkey with a serial number. What does this artifact indicate?

⚠ Common exam trap

EC-Council often tests the misconception that all USB devices (e.g., keyboards, printers) are logged under the same 'USBSTOR' key, but in reality, only mass storage devices appear there, while other USB classes have separate enumeration paths.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A USB storage device was attached

The registry key 'HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR' specifically enumerates USB mass storage devices (e.g., flash drives, external hard drives). The presence of a subkey with a serial number indicates that a USB storage device was attached and recognized by the Windows operating system, as the serial number uniquely identifies the device. This key is a primary artifact in USB forensics for tracking storage device connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A USB network adapter was attached

    Why it's wrong here

    USB network adapters (Ethernet or Wi-Fi dongles) are enumerated under the NET class GUID in HKLM\SYSTEM\CurrentControlSet\Enum, not under USBSTOR. USBSTOR exists exclusively for USB mass-storage devices (flash drives, external disks) that implement the USB Mass Storage Class (class code 08). Therefore, an artifact in USBSTOR indicates storage media attachment, not network hardware attachment.

  • ✓

    A USB storage device was attached

    Why this is correct

    The USBSTOR subkey in HKLM\SYSTEM\CurrentControlSet\Enum is populated when Windows enumerates a USB mass-storage device, such as a flash drive, external HDD, or card reader. It creates a subkey named like Disk&Ven_<vid>&Prod_<pid>&Rev_<rev>, and the key's LastWrite time can be used as forensic timeline evidence of the device's most recent connection to the system. This is why this key points directly to a USB storage device.

  • ✗

    A USB printer was attached

    Why it's wrong here

    USB printers do not appear in USBSTOR; they are enumerated either under the 'PRINT' class or as a USB interface class 07 device under HKLM\SYSTEM\CurrentControlSet\Enum\USB\VID_... using the printer interface descriptor. USBSTOR is reserved for storage devices with USB class code 08 (Mass Storage), so a printer lacks the required storage interface and cannot generate an entry there.

  • ✗

    A USB keyboard was attached

    Why it's wrong here

    A USB keyboard is a Human Interface Device (HID) and is enumerated under HKLM\SYSTEM\CurrentControlSet\Enum\HID, using a usage page of 0x01 and usage ID 0x06 for keyboards, or under the USB key with HID interface class 03. USBSTOR only records mass-storage devices, so a keyboard does not produce a USBSTOR key. Thus, observing USBSTOR entries cannot be used to infer keyboard attachment.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.