Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

EC-Council 212-89 Exam - Topic 1 Question 100 Discussion

Following a security alert, the incident response team at a legal consulting firm suspects that an employee used a USB storage device to exfiltrate confidential client data. To confirm which USB device was connected and gather timestamps and identifiers, which method is most effective?
A) Check Windows registry entries under Enum\USB.
B) Scan network logs for USB file upload patterns.
C) Review Windows SetupAPI.dev.log file entries.
D) Use WHOIS lookup to trace USB activity.

EC-Council 212-89 Exam - Topic 1 Question 100 Discussion

Actual exam question for EC-Council's 212-89 exam
Question #: 100
Topic #: 1
[All 212-89 Questions]

Following a security alert, the incident response team at a legal consulting firm suspects that an employee used a USB storage device to exfiltrate confidential client data. To confirm which USB device was connected and gather timestamps and identifiers, which method is most effective?

Show Suggested Answer Hide Answer
Suggested Answer: A

ECIH forensic readiness guidance identifies the Windows Registry as a primary source for USB device artifacts. The EnumUSB registry key stores vendor IDs, product IDs, serial numbers, and connection history.

Option A is correct because it provides direct evidence of which USB devices were connected, when they were installed, and on which system---critical for insider investigations.

Option B cannot reliably identify physical USB usage. Option C contains driver installation data but is less comprehensive. Option D is irrelevant.

Registry analysis is a foundational forensic technique in ECIH, making Option A correct.


Contribute your Thoughts:

0/2000 characters
Aliza
3 days ago
Definitely A, it's the most direct method for USB tracking.
upvoted 0 times
...
Pearly
8 days ago
Wait, D) WHOIS lookup for USB? That sounds off.
upvoted 0 times
...
Aliza
14 days ago
C) Reviewing the SetupAPI log is super effective too!
upvoted 0 times
...
Dino
19 days ago
I disagree, B) Scan network logs might reveal more.
upvoted 0 times
...
Leontine
24 days ago
A) Check Windows registry entries under Enum\USB is the way to go.
upvoted 0 times
...
Pansy
29 days ago
WHOIS lookup seems off for this question; I don't think it relates to USB activity at all.
upvoted 0 times
...
Harrison
1 month ago
I feel like scanning network logs could help, but it might not give the specific device info we need.
upvoted 0 times
...
Afton
1 month ago
I'm not entirely sure, but I remember something about the SetupAPI log being useful for tracking USB connections too.
upvoted 0 times
...
Jenelle
1 month ago
I think checking the Windows registry entries might be the best option since it can show connected devices and timestamps.
upvoted 0 times
...

Save Cancel