A security analyst is reviewing a Windows 10 workstation that is suspected of being infected with malware. The analyst notices unusual network traffic and wants to identify the malware's persistence mechanism. Which of the following Windows locations should the analyst check? (Choose two.)
Trap 1: The Event Viewer Security log
The Security log records security-related events like logon attempts and privilege use, but it does not list programs that run at startup. While it might show evidence of malware execution, it does not reveal persistence mechanisms directly. Analyzing the Security log is useful for auditing but not for identifying autostart locations.
Trap 2: The Task Scheduler library
Task Scheduler can be used by malware to schedule tasks, which is a persistence method. However, the question asks for two locations, and while Task Scheduler is valid, the most common and primary locations are the Run key and Startup folders. Task Scheduler is also a persistence mechanism, but it is not as universally checked as the other two. The question specifies 'persistence mechanism' and both A and C are classic. Including E would be correct if three were allowed, but only two are correct.
Trap 3: The folder C:\Windows\System32\drivers\etc\hosts
The hosts file is used for local DNS resolution and can be modified by malware to redirect traffic, but it is not a persistence mechanism. It does not cause programs to run automatically. While it can be part of an attack, it does not maintain persistence across reboots. Therefore, it is not a primary location to check for persistence.
- A
The Event Viewer Security log
Why it fails: The Security log records security-related events like logon attempts and privilege use, but it does not list programs that run at startup. While it might show evidence of malware execution, it does not reveal persistence mechanisms directly. Analyzing the Security log is useful for auditing but not for identifying autostart locations.
- B
The Startup folder for the current user and all users
The Startup folders contain shortcuts to programs that run automatically when a user logs in. Malware frequently places shortcuts here to achieve persistence. Checking both the user-specific and all-users Startup folders is essential, as they are common and easy to exploit for maintaining a foothold on the system.
- C
The Task Scheduler library
Why it fails: Task Scheduler can be used by malware to schedule tasks, which is a persistence method. However, the question asks for two locations, and while Task Scheduler is valid, the most common and primary locations are the Run key and Startup folders. Task Scheduler is also a persistence mechanism, but it is not as universally checked as the other two. The question specifies 'persistence mechanism' and both A and C are classic. Including E would be correct if three were allowed, but only two are correct.
- D
The Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
This Registry key is a common location for malware to establish persistence, as programs listed here run automatically at startup. Malware often adds entries to this key to ensure it executes each time the user logs in. Checking this key is a standard step in malware analysis and can reveal suspicious executables.
- E
The folder C:\Windows\System32\drivers\etc\hosts
Why it fails: The hosts file is used for local DNS resolution and can be modified by malware to redirect traffic, but it is not a persistence mechanism. It does not cause programs to run automatically. While it can be part of an attack, it does not maintain persistence across reboots. Therefore, it is not a primary location to check for persistence.