CEH Practice Question: Malware, Social Engineering and Network Attacks
A security analyst is investigating a malware incident. The analyst observes that the malware creates a scheduled task to run a script every time the system starts, and it also modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run to execute a payload. Which two persistence techniques is the malware using? (Choose two.)
⚠ Common exam trap
The trap here is assuming that any mention of 'startup' implies a service or bootkit, but the specific artifacts named—scheduled task and HKCU Run key—are the definitive indicators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Registry Run key
The malware uses two persistence techniques: creating a scheduled task to run at startup and modifying the registry Run key to execute a payload on user logon. Both are explicitly described in the scenario. The other options are different persistence methods not mentioned.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Bootkit
Why it's wrong here
A bootkit infects the master boot record (MBR) or volume boot record (VBR) to load before the operating system. The scenario does not indicate any boot-level infection; it only mentions scheduled tasks and registry Run keys. Thus, bootkit is not applicable here.
- ✓
Registry Run key
Why this is correct
The scenario explicitly mentions modification of the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key, which is a classic registry Run key persistence method. This key causes the specified program to execute automatically when the user logs on. Therefore, this is one of the correct answers.
- ✗
Service creation
Why it's wrong here
Service creation involves installing a Windows service to run automatically at boot. The scenario does not mention creation of a new service; it mentions a scheduled task and a registry Run key. Therefore, service creation is not a persistence technique used here.
- ✗
DLL hijacking
Why it's wrong here
DLL hijacking is a technique where a malicious DLL is placed in a location where a legitimate application will load it. The scenario does not describe any DLL hijacking; it focuses on scheduled tasks and registry modifications. Hence, this is not a correct answer.
- ✓
Scheduled task
Why this is correct
The malware creates a scheduled task to run a script at system startup, as stated in the scenario. Scheduled tasks are a common persistence mechanism that can trigger execution at boot, logon, or on a schedule. Thus, this is the other correct answer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.