Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI USBSTOR Practice Question

An investigator is analyzing a Windows system and wants to find evidence of USB device usage. Which TWO registry keys should be examined? (Select TWO.)

⚠ Common exam trap

EC-Council often tests the distinction between system-wide device enumeration (USBSTOR) and user-specific mount point history (MountPoints2), leading candidates to mistakenly select startup or profile keys that have no connection to USB artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR

Option C, HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR, is correct because this key is where Windows records every USB mass-storage device that has ever been connected, storing device instance IDs, vendor/product identifiers, and serial numbers that directly evidence USB storage usage. Option D, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2, is correct because it tracks per-user mount points and drive-letter assignments for mounted volumes, including USB drives, showing which user mounted which removable device. Option A, HKLM\SAM\SAM, is incorrect because the SAM hive stores local account and group security data, not USB device artifacts. Option B, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, is incorrect because it lists programs configured to auto-start at logon, which is persistence-related rather than USB-usage evidence. Option E, HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList, is incorrect because it maps user SIDs to profile paths, not USB device connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKLM\SAM\SAM

    Why it's wrong here

    HKLM\SAM\SAM is the Security Accounts Manager database, storing local user account credentials and NTLM password hashes. It contains no USB device identifiers, serial numbers, or volume information; its forensic relevance lies in user credential extraction, not peripheral device history. Therefore, it would not be used to determine which USB storage devices were connected to the system.

  • ✗

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    Why it's wrong here

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a per-user autostart registry key used to execute programs at logon. While it may reveal malware persistence or unusual executables launched from removable media, it does not record device identification data, connection times, or mount information for USB drives. Thus it is irrelevant to USB device artifact analysis.

  • ✓

    HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR

    Why this is correct

    HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR is the definitive system-wide registry hive for USB mass storage devices. Each subkey corresponds to a unique device instance, following the pattern Disk&Ven_[vendor]&Prod_[product]&Rev_[revision], with a serial-number subkey that can identify the exact device. It also contains the ParentIdPrefix value, which can be correlated with other artifacts such as Setupapi.dev.log and MountPoints2 to establish connection timelines. This key is a primary source for listing all USB storage devices ever plugged into the system.

  • ✓

    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

    Why this is correct

    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 is a per-user registry key that stores explorer's volume mount points, including those for USB drives, usually identified by the volume GUID and sometimes by drive letter. Under each subkey, the value data often includes Shell icon paths and desktop.ini configuration, and its last write time can indicate when the user last accessed that volume. Because it is user-hive-based, it can help associate a particular user account with USB drive usage, complementing the system-level USBSTOR enumeration.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList

    Why it's wrong here

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList contains a list of user profiles, indexing them by security identifier (SID) and mapping each to a ProfileImagePath. This key is used to locate profile directories and load user hive information, not to track external storage or USB device connections. Therefore, it is entirely unrelated to USB forensic analysis.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.