GSEC Windows Forensics Practice Question
An examiner is reviewing a Windows 11 workstation seized during an insider-threat investigation. The suspect denies ever connecting removable media, but the examiner finds a file named 'E01' inside 'C:\Windows\INF\' with no corresponding setupapi.dev.log entries for USB devices. Which artifact should the examiner correlate to confirm the specific USB storage device that was connected and its serial number?
⚠ Common exam trap
The trap here is assuming that the absence of setupapi.dev.log entries means no USB device was ever connected, ignoring the persistent USBSTOR registry key that records device serial numbers independently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The USBSTOR registry key under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
The USBSTOR registry key is the authoritative artifact for identifying USB mass-storage devices that have been attached to a Windows system. Each subkey contains a unique device instance ID that includes the vendor, product, and serial number, allowing an examiner to confirm the exact device even when setupapi.dev.log entries are absent or incomplete. Correlating USBSTOR with other artifacts provides a robust evidentiary link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The NTFS USN journal on the system volume
Why it's wrong here
The USN journal records changes to files and directories on an NTFS volume, including creation and deletion events, but it does not capture USB device connection details or serial numbers. It could show that a file was created, but it cannot tie that activity to a specific removable device. Therefore it does not resolve the suspect's denial of connecting USB storage.
- ✓
The USBSTOR registry key under HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
Why this is correct
USBSTOR records every USB mass-storage device that has been connected, storing the device descriptor, vendor, product, and a unique serial number in the subkey name. Correlating the serial in USBSTOR with setupapi.dev.log entries confirms the specific device even when log entries appear missing, because USBSTOR persists after disconnection and can survive log rotation or selective deletion. This directly addresses the insider-threat scenario.
- ✗
The MountedDevices registry key under HKLM\SYSTEM\MountedDevices
Why it's wrong here
MountedDevices maps drive letters to volume GUIDs and disk signatures, which can indicate that a volume was mounted, but it does not record the USB vendor, product, or serial number of the device. It cannot confirm the specific USB storage device or its serial, so it fails to answer the examiner's need. It also may contain entries for internal volumes, adding ambiguity.
- ✗
The Windows Portable Devices (WPD) registry key under HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices
Why it's wrong here
WPD tracks portable devices such as media players and phones, not USB mass-storage devices like flash drives. While it can show device names, it typically lacks the serial number and storage-specific details that USBSTOR provides. In this scenario, the suspect's claim concerns USB storage, so WPD is not the appropriate artifact to confirm the device.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.