Courseiva
Windows Forensics →mediumMultiple Select

GSEC Windows Forensics Practice Question

An analyst is examining a Windows 10 host suspected of being used to stage and exfiltrate data. The analyst wants to identify evidence of files that were recently opened or created by the user, and of USB mass storage devices that were previously connected. Which two artifacts should the analyst examine to address these goals? (Choose two.)

⚠ Common exam trap

The trap here is reaching for application-usage or network-usage artifacts that feel related to user activity but do not actually enumerate recently opened documents or previously connected USB mass storage devices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SYSTEM hive's USBSTOR key at ControlSet001\Enum\USBSTOR

RecentDocs in NTUSER.DAT preserves recently opened documents with shell item paths, addressing the recent-file goal, while the SYSTEM hive's USBSTOR key enumerates USB mass storage devices that were previously connected. Together they cover both investigative objectives. The other artifacts either record application usage, executable metadata, or network statistics, none of which map to the stated goals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The RecentApps key under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Search

    Why it's wrong here

    The RecentApps key tracks applications the user launched from the Start menu or search, storing entries that help reconstruct program usage. It does not record individual file opens or created documents, and it has no bearing on USB device history. It is useful for showing that an application ran, but it will not satisfy either of the two investigative goals in this scenario.

  • ✗

    The Amcache.hve Root\File key

    Why it's wrong here

    Amcache's File key stores metadata about executables, including paths, sizes, and SHA-1 hashes, and is used to show that an executable existed on the system. It is not designed to enumerate user document activity or USB mass storage connections. It therefore does not answer either of the two investigative questions posed in this scenario.

  • ✓

    The SYSTEM hive's USBSTOR key at ControlSet001\Enum\USBSTOR

    Why this is correct

    The USBSTOR key in the SYSTEM hive records USB mass storage devices that have been connected to the host, including device identifiers, serial numbers, and friendly names. It is the primary artifact for proving prior USB mass storage connections. It does not track individual file opens, so it addresses the USB portion of the investigation rather than the recent-file portion.

  • ✗

    The SRUM database's Network Data Usage table

    Why it's wrong here

    The SRUM Network Data Usage table records per-application bytes sent and received over time, which can support exfiltration timelines. It does not enumerate recently opened user files or list previously connected USB mass storage devices. While it is relevant to the broader exfiltration case, it does not satisfy either of the two specific artifact goals stated in the stem.

  • ✓

    The RecentDocs key under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

    Why this is correct

    The RecentDocs key, maintained per user in NTUSER.DAT, stores the most recently opened documents by extension along with shell item data that can include the original path and volume. It directly supports identifying files the user recently opened or created. It does not, however, cover USB device connection history, so it addresses only one of the two stated goals.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.