nerdexam
EC-Council

312-49 · Question #595

Smith, an employee of a reputed forensic investigation firm, has been hired by a private organization to investigate a laptop that is suspected to be involved in the hacking of the organization's DC…

The correct answer is D. RunMRU key. This question asks for the specific Windows registry key that stores commands and paths entered into the Run dialog box.

Submitted by cyberguy42· Apr 18, 2026Disk Forensics

Question

Smith, an employee of a reputed forensic investigation firm, has been hired by a private organization to investigate a laptop that is suspected to be involved in the hacking of the organization's DC server. Smith wants to find all the values typed into the Run box in the Start menu. Which of the following registry keys will Smith check to find the above information?

Options

  • ATypedURLs key
  • BMountedDevices key
  • CUserAssist Key
  • DRunMRU key

How the community answered

(31 responses)
  • B
    3% (1)
  • C
    6% (2)
  • D
    90% (28)

Why each option

This question asks for the specific Windows registry key that stores commands and paths entered into the Run dialog box.

ATypedURLs key

The TypedURLs key stores URLs typed into the address bar of Internet Explorer, not commands entered into the Run box.

BMountedDevices key

The MountedDevices key stores information about devices mounted to the system, such as hard drives and USB devices, not user-typed commands.

CUserAssist Key

The UserAssist key tracks GUI application execution and access times but does not specifically store the exact commands typed into the Run dialog.

DRunMRU keyCorrect

The RunMRU (Most Recently Used) registry key, typically found under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU, stores a list of commands and paths that a user has typed into the Run dialog box, making it a valuable forensic artifact for user activity.

Concept tested: Windows registry forensics (RunMRU key)

Source: https://learn.microsoft.com/en-us/windows/win32/shell/runmru

Topics

#Windows Registry#Forensic Artifacts#Run Box History#Digital Forensics

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice