CHFI USBSTOR Practice Question
An investigator is analyzing a Windows system and wants to find evidence of USB device usage. Which TWO registry keys should be examined? (Select TWO.)
⚠ Common exam trap
EC-Council often tests the distinction between system-wide device enumeration (USBSTOR) and user-specific mount point history (MountPoints2), leading candidates to mistakenly select startup or profile keys that have no connection to USB artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Option C, HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR, is correct because this key is where Windows records every USB mass-storage device that has ever been connected, storing device instance IDs, vendor/product identifiers, and serial numbers that directly evidence USB storage usage. Option D, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2, is correct because it tracks per-user mount points and drive-letter assignments for mounted volumes, including USB drives, showing which user mounted which removable device. Option A, HKLM\SAM\SAM, is incorrect because the SAM hive stores local account and group security data, not USB device artifacts. Option B, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, is incorrect because it lists programs configured to auto-start at logon, which is persistence-related rather than USB-usage evidence. Option E, HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList, is incorrect because it maps user SIDs to profile paths, not USB device connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HKLM\SAM\SAM
Why it's wrong here
HKLM\SAM\SAM is the Security Accounts Manager database, storing local user account credentials and NTLM password hashes. It contains no USB device identifiers, serial numbers, or volume information; its forensic relevance lies in user credential extraction, not peripheral device history. Therefore, it would not be used to determine which USB storage devices were connected to the system.
- ✗
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a per-user autostart registry key used to execute programs at logon. While it may reveal malware persistence or unusual executables launched from removable media, it does not record device identification data, connection times, or mount information for USB drives. Thus it is irrelevant to USB device artifact analysis.
- ✓
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Why this is correct
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the definitive system-wide registry hive for USB mass storage devices. Each subkey corresponds to a unique device instance, following the pattern Disk&Ven_[vendor]&Prod_[product]&Rev_[revision], with a serial-number subkey that can identify the exact device. It also contains the ParentIdPrefix value, which can be correlated with other artifacts such as Setupapi.dev.log and MountPoints2 to establish connection timelines. This key is a primary source for listing all USB storage devices ever plugged into the system.
- ✓
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
Why this is correct
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 is a per-user registry key that stores explorer's volume mount points, including those for USB drives, usually identified by the volume GUID and sometimes by drive letter. Under each subkey, the value data often includes Shell icon paths and desktop.ini configuration, and its last write time can indicate when the user last accessed that volume. Because it is user-hive-based, it can help associate a particular user account with USB drive usage, complementing the system-level USBSTOR enumeration.
- ✗
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
Why it's wrong here
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList contains a list of user profiles, indexing them by security identifier (SID) and mapping each to a ProfileImagePath. This key is used to locate profile directories and load user hive information, not to track external storage or USB device connections. Therefore, it is entirely unrelated to USB forensic analysis.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.