GCFA Windows Artifact Analysis Practice Question
An analyst is examining a Windows 10 system to determine if a specific USB device was connected. The analyst has already checked the registry and found no trace in USBSTOR. Which TWO additional artifacts should the analyst examine to corroborate USB device connection? (Choose two.)
⚠ Common exam trap
The trap here is relying solely on the USBSTOR registry key, which can be cleared by anti-forensic tools or simply not present in some cases, while overlooking other logs that record device installation and connection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Setupapi.dev.log
Setupapi.dev.log and the Microsoft-Windows-DriverFrameworks-UserMode/Operational event log both record USB device installation and connection events with timestamps and device identifiers. These artifacts can provide evidence of a USB device even if the USBSTOR registry key has been cleared, making them essential for corroboration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prefetch files for USBSTOR.SYS
Why it's wrong here
Prefetch files for USBSTOR.SYS would indicate that the USB storage driver was loaded, but this occurs whenever any USB storage device is connected, not necessarily a specific device. It does not provide details like device serial number or connection timestamps. Thus, it is not a specific artifact for corroborating a particular USB device's connection.
- ✗
Registry key: HKLM\SYSTEM\CurrentControlSet\Enum\USB
Why it's wrong here
The USB key under Enum stores information about USB devices that have been connected, but if the analyst has already checked USBSTOR and found nothing, this key may also be empty or have limited data. It is not as reliable as Setupapi.dev.log or the DriverFrameworks log for corroborating connection, especially if anti-forensics were used.
- ✓
Setupapi.dev.log
Why this is correct
Setupapi.dev.log records device installation and driver setup events, including USB devices. It can contain the device's vendor and product IDs, serial number, and timestamps of when the device was first connected. This makes it a valuable artifact for corroborating USB connection, especially when USBSTOR is cleared.
- ✓
Windows Event Log: Microsoft-Windows-DriverFrameworks-UserMode/Operational
Why this is correct
This event log contains events related to user-mode drivers, including USB device arrival and removal. Event IDs 2003, 2004, 2005, and 2006 can indicate when a USB device was connected or disconnected, providing timestamps and device identifiers. It is a reliable source for corroborating USB connection when USBSTOR is unavailable.
- ✗
NTFS $MFT
Why it's wrong here
The Master File Table ($MFT) records metadata for files and directories on an NTFS volume, but it does not track USB device connections. While it may show files copied from a USB device, it does not provide direct evidence of the device itself being connected. Therefore, it is not a primary artifact for USB connection analysis.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.