CHFI OS and Network Forensics Practice Question
An analyst reviews Windows Registry for USB device usage history. Which registry hive and key contain the 'USBSTOR' key that logs unique serial numbers of connected USB drives?
⚠ Common exam trap
EC-CHFI often tests the misconception that USB device history is stored in user-specific hives (HKCU) or in the SAM hive, when in fact the SYSTEM hive's Enum\USBSTOR key is the authoritative source for device serial numbers and connection metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
The USBSTOR key is located under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR and logs each unique USB device by its serial number. This hive is part of the SYSTEM registry, which maintains device enumeration data used by the Plug and Play manager to track connected hardware. Forensic analysts examine this key to identify USB drive insertion history, including first and last connection timestamps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HKLM\SAM\SAM\Domains\Account\Users
Why it's wrong here
The HKLM\SAM\SAM\Domains\Account\Users key is the core of the Security Accounts Manager database, storing user account SIDs, group memberships, and password hashes (often in the V value). It contains absolutely no plug-and-play device enumeration data, such as USB vendor IDs, product IDs, or serial numbers. While a forensic examiner may parse this hive to identify user accounts or recover login artifacts, it is irrelevant to tracing USB storage device history because USB device records are maintained by the System hive's Enum branch, not by the SAM hive.
- ✗
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
Why it's wrong here
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 is a per-user registry key that caches shell namespace mount points for volumes and drives, represented by volume GUIDs like {abcdef01-1234-5678-9abc-def012345678}. It records drive-letter assignments and autoplay-related settings, but it does not store the device's USB vendor, product, or serial identifier—those fields live under SYSTEM\CurrentControlSet\Enum\USBSTOR. Additionally, this key can include non-USB volumes such as network shares and internal partitions, making it a weak and ambiguous indicator of USB device usage compared to the authoritative hardware enumerator.
- ✓
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Why this is correct
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the definitive Windows Plug and Play key for USB storage devices, where each subkey is named with the device instance ID (e.g., Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00) and a unique serial number. These subkeys persist even after the device is removed, and their LastWriteTime can estimate when the device was last connected, while the FriendlyName and ParentIdPrefix values enrich the picture. Being under the SYSTEM hive, it is machine-wide rather than user-specific, making it the first place investigators query to build a timeline of external storage devices that touched a system.
- ✗
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
Why it's wrong here
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList contains a subkey for each user profile, keyed by the user's SID, with values such as ProfileImagePath, RefCount, and State that map SIDs to local user profile directories. It does not enumerate hardware or USB devices at all; its purpose is to maintain profile loading and cleanup data, and any USB-related artifact would be absent by design. Analysts may use this key to link a user SID to a profile folder when correlating user activity, but it cannot serve as a source for USB device usage history.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.