CHFI OS and Network Forensics Practice Question
A forensic analyst discovers an unusual entry in the Windows Registry under 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which persistence mechanism does this represent?
⚠ Common exam trap
EC-Council CHFI often tests the distinction between user-specific (HKCU) and system-wide (HKLM) Run keys, and candidates may confuse the Run key with other persistence mechanisms like scheduled tasks or services, but the key path explicitly identifies it as a Registry Run key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Registry Run key persistence
The registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' is a standard Windows Registry Run key that automatically launches specified programs when a user logs in. This is a well-known persistence mechanism used by both legitimate software and malware to maintain foothold on a system. The presence of an unusual entry here indicates an attempt to achieve persistence via the registry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Registry Run key persistence
Why this is correct
The Run key is a Windows AutoStart Extensibility Point (ASEP) located in both HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, causing the referenced executable to launch each time a user logs on. An unusual entry here, often a command line pointing to a portable executable in a temp directory, is a classic persistence mechanism used by malware. Because the Run key is queried at logon and is a single value, it is one of the simplest and most frequently abused persistences in Windows, and its presence is a strong indicator of compromise when the entry is not associated with a legitimate installed program.
- ✗
Service installation
Why it's wrong here
Service installation is an alternative persistence technique that involves creating a new Windows service under the registry key HKLM\SYSTEM\CurrentControlSet\Services, where each subkey contains an ImagePath that points to an executable the Service Control Manager (SCM) runs. Unlike a Run key entry, a service requires an administrator-level installation process to register a ServiceMain function and set the Start value to 2 (AUTO_START) or 3 (DEMAND_START), and it executes before or during system startup rather than at a user logon. Therefore, an unusual entry specifically in a Run key is not a service, and the two locations are distinct from a forensic perspective.
- ✗
Scheduled task
Why it's wrong here
Scheduled tasks are stored in the Task Scheduler database, typically as XML files under C:\Windows\System32\Tasks (or within the registry under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache), and they are triggered based on time, event, or system state—not by the registry Run key. The Run key is only one of many AutoStart Extensibility Points, and a scheduled task would not appear as a stray value in the Run key because it lives in a completely separate namespace. When investigating a suspicious Run key value, an analyst should check Task Scheduler separately to identify tasks that may have been created for persistence, as the two mechanisms are indistinguishable in terms of malicious intent but have different forensic evidence locations.
- ✗
Startup folder
Why it's wrong here
The Startup folder is a file-system directory, located in the user's profile under C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (and the common counterpart for all users), that contains shortcuts or executables which are launched at user logon. It is not part of the registry and does not involve a Run key value; an unusual registry entry under a Run key cannot be attributed to a Startup folder item. From a forensic standpoint, the Startup folder is far easier for the user to spot and manually manage, whereas the Run key is hidden within the registry and thus a more stealthy persistence alternative.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.