Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

An analyst reviews Windows Registry for USB device usage history. Which registry hive and key contain the 'USBSTOR' key that logs unique serial numbers of connected USB drives?

⚠ Common exam trap

EC-CHFI often tests the misconception that USB device history is stored in user-specific hives (HKCU) or in the SAM hive, when in fact the SYSTEM hive's Enum\USBSTOR key is the authoritative source for device serial numbers and connection metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR

The USBSTOR key is located under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR and logs each unique USB device by its serial number. This hive is part of the SYSTEM registry, which maintains device enumeration data used by the Plug and Play manager to track connected hardware. Forensic analysts examine this key to identify USB drive insertion history, including first and last connection timestamps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKLM\SAM\SAM\Domains\Account\Users

    Why it's wrong here

    The HKLM\SAM\SAM\Domains\Account\Users key is the core of the Security Accounts Manager database, storing user account SIDs, group memberships, and password hashes (often in the V value). It contains absolutely no plug-and-play device enumeration data, such as USB vendor IDs, product IDs, or serial numbers. While a forensic examiner may parse this hive to identify user accounts or recover login artifacts, it is irrelevant to tracing USB storage device history because USB device records are maintained by the System hive's Enum branch, not by the SAM hive.

  • ✗

    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

    Why it's wrong here

    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 is a per-user registry key that caches shell namespace mount points for volumes and drives, represented by volume GUIDs like {abcdef01-1234-5678-9abc-def012345678}. It records drive-letter assignments and autoplay-related settings, but it does not store the device's USB vendor, product, or serial identifier—those fields live under SYSTEM\CurrentControlSet\Enum\USBSTOR. Additionally, this key can include non-USB volumes such as network shares and internal partitions, making it a weak and ambiguous indicator of USB device usage compared to the authoritative hardware enumerator.

  • ✓

    HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR

    Why this is correct

    HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the definitive Windows Plug and Play key for USB storage devices, where each subkey is named with the device instance ID (e.g., Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00) and a unique serial number. These subkeys persist even after the device is removed, and their LastWriteTime can estimate when the device was last connected, while the FriendlyName and ParentIdPrefix values enrich the picture. Being under the SYSTEM hive, it is machine-wide rather than user-specific, making it the first place investigators query to build a timeline of external storage devices that touched a system.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList

    Why it's wrong here

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList contains a subkey for each user profile, keyed by the user's SID, with values such as ProfileImagePath, RefCount, and State that map SIDs to local user profile directories. It does not enumerate hardware or USB devices at all; its purpose is to maintain profile loading and cleanup data, and any USB-related artifact would be absent by design. Analysts may use this key to link a user SID to a profile folder when correlating user activity, but it cannot serve as a source for USB device usage history.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.