Following a security alert, the incident response team at a legal consulting firm suspects that an employee used a USB storage device to exfiltrate confidential client data. To confirm which USB device was connected and gather timestamps and identifiers, which method is most effective?
ECIH forensic readiness guidance identifies the Windows Registry as a primary source for USB device artifacts. The EnumUSB registry key stores vendor IDs, product IDs, serial numbers, and connection history.
Option A is correct because it provides direct evidence of which USB devices were connected, when they were installed, and on which system---critical for insider investigations.
Option B cannot reliably identify physical USB usage. Option C contains driver installation data but is less comprehensive. Option D is irrelevant.
Registry analysis is a foundational forensic technique in ECIH, making Option A correct.
Currently there are no comments in this discussion, be the first to comment!