Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 212-89 Exam - Topic 1 Question 100 Discussion

Following a security alert, the incident response team at a legal consulting firm suspects that an employee used a USB storage device to exfiltrate confidential client data. To confirm which USB device was connected and gather timestamps and identifiers, which method is most effective?
A) Check Windows registry entries under Enum\USB.
B) Scan network logs for USB file upload patterns.
C) Review Windows SetupAPI.dev.log file entries.
D) Use WHOIS lookup to trace USB activity.

Eccouncil 212-89 Exam - Topic 1 Question 100 Discussion

Actual exam question for Eccouncil's 212-89 exam
Question #: 100
Topic #: 1
[All 212-89 Questions]

Following a security alert, the incident response team at a legal consulting firm suspects that an employee used a USB storage device to exfiltrate confidential client data. To confirm which USB device was connected and gather timestamps and identifiers, which method is most effective?

Show Suggested Answer Hide Answer
Suggested Answer: A

ECIH forensic readiness guidance identifies the Windows Registry as a primary source for USB device artifacts. The EnumUSB registry key stores vendor IDs, product IDs, serial numbers, and connection history.

Option A is correct because it provides direct evidence of which USB devices were connected, when they were installed, and on which system---critical for insider investigations.

Option B cannot reliably identify physical USB usage. Option C contains driver installation data but is less comprehensive. Option D is irrelevant.

Registry analysis is a foundational forensic technique in ECIH, making Option A correct.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel