Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

A security analyst is investigating a malware incident. The analyst observes that the malware creates a scheduled task to run a script every time the system starts, and it also modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run to execute a payload. Which two persistence techniques is the malware using? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any mention of 'startup' implies a service or bootkit, but the specific artifacts named—scheduled task and HKCU Run key—are the definitive indicators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Registry Run key

The malware uses two persistence techniques: creating a scheduled task to run at startup and modifying the registry Run key to execute a payload on user logon. Both are explicitly described in the scenario. The other options are different persistence methods not mentioned.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Bootkit

    Why it's wrong here

    A bootkit infects the master boot record (MBR) or volume boot record (VBR) to load before the operating system. The scenario does not indicate any boot-level infection; it only mentions scheduled tasks and registry Run keys. Thus, bootkit is not applicable here.

  • ✓

    Registry Run key

    Why this is correct

    The scenario explicitly mentions modification of the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, which is a classic registry Run key persistence method. This key causes the specified program to execute automatically when the user logs on. Therefore, this is one of the correct answers.

  • ✗

    Service creation

    Why it's wrong here

    Service creation involves installing a Windows service to run automatically at boot. The scenario does not mention creation of a new service; it mentions a scheduled task and a registry Run key. Therefore, service creation is not a persistence technique used here.

  • ✗

    DLL hijacking

    Why it's wrong here

    DLL hijacking is a technique where a malicious DLL is placed in a location where a legitimate application will load it. The scenario does not describe any DLL hijacking; it focuses on scheduled tasks and registry modifications. Hence, this is not a correct answer.

  • ✓

    Scheduled task

    Why this is correct

    The malware creates a scheduled task to run a script at system startup, as stated in the scenario. Scheduled tasks are a common persistence mechanism that can trigger execution at boot, logon, or on a schedule. Thus, this is the other correct answer.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.