CHFI OS and Network Forensics Practice Question
In Windows registry forensics, which key is examined to identify USB devices that were connected to the system?
⚠ Common exam trap
EC-Council often tests the distinction between the hardware enumeration key (USBSTOR) and the user-specific mount point key (MountPoints2), leading candidates to choose the latter because it appears more directly related to 'connected devices' in the registry path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
The USBSTOR key under HKLM\SYSTEM\CurrentControlSet\Enum contains a subkey for each USB mass storage device that has ever been connected to the system, recording the device's serial number, class, and instance ID. This is the primary forensic artifact for identifying USB device connection history because the system enumerates and persists these entries when a USB storage device is first plugged in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
The HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key is a per-machine autostart entry point that lists applications launched at user logon. Forensic examiners often inspect this key to identify persistent malware or rogue executables, but it contains no device enumeration data, serial numbers, or hardware identifiers. USB storage devices are not registered as run entries, so this key cannot provide any evidence of an external drive's connection history. Its forensic value lies in persistence analysis, not device identification.
- ✗
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
Why it's wrong here
The per-user NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 key tracks drive-letter and volume GUID mappings that Explorer has displayed, capturing shell folder information for mounted volumes. While it can reveal that a drive letter was assigned to a removable volume and the volume's GUID, it does not routinely store the USB device's vendor ID, product ID, or unique serial number in a parseable format. Additionally, this key is overwritten or cleared when a drive is unplugged or the user manually removes the mapping, making it an unreliable source for confirming which physical USB device was used. Therefore, it is a complementary artifact, not the primary key for USB device identification.
- ✗
HKLM\SAM\SAM\Domains\Account\Users
Why it's wrong here
The HKLM\SAM\SAM\Domains\Account\Users subkey is the heart of the Security Account Manager, storing each local user account's relative identifier (RID), password hash, and other authentication-related data. This hive is a prime target for credential theft, but it is entirely hardware-agnostic and contains no classes, instances, or descriptors for external peripherals. USB storage device identifiers such as 'Disk&Ven_...' appear nowhere within the SAM tree, so analyzing this key for USB history would be an investigative dead end. Its analysis is reserved for user account and login forensics, not device enumeration.
- ✓
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Why this is correct
The HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR key is the definitive registry artifact for identifying USB mass storage devices that have been connected to a Windows system. Under this key, the Plug and Play manager creates a subtree in which each vendor/product pair (e.g., Disk&Ven_Kingston&Prod_DataTraveler&Rev_1.00) appears, and beneath that, a unique device instance key named with the device's reported serial number. Forensic examiners can extract the device instance's LastWrite time and the FriendlyName value to confirm both the exact drive and its approximate last connection time. Because the system records this information even after the device is removed, it is the correct key to examine in registry-based USB forensic investigations.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.