Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic analyst is examining a Windows system for evidence of a program that runs automatically every time the system starts. Which registry key is commonly used to achieve persistence via the 'Run' key?

⚠ Common exam trap

CHFI often tests the distinction between the 'Run' key and the 'Services' key (option D), as candidates may confuse auto-start services with the simpler 'Run' registry persistence mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

The 'Run' key at HKLM\Software\Microsoft\Windows\CurrentVersion\Run is the standard registry location used by legitimate software and malware alike to execute a program automatically at every system startup. This key stores values that point to executable paths, and Windows’ Winlogon process reads these values during boot to launch the specified programs. It is a primary persistence mechanism in Windows forensics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKLM\SAM\SAM

    Why it's wrong here

    The HKLM\SAM\SAM hive stores the Security Account Manager database, which contains user account information and password hash material, but no directives for launching applications at boot or logon. Because access to this hive is locked to the SYSTEM account, it is relevant only to credential-related investigations, not to startup program analysis. Therefore, an examiner looking for evidence of an executable that runs automatically should not expect to find it under this key.

  • ✓

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    Why this is correct

    This key is the per-machine Run key and is one of the classic autostart locations processed when a user logs on. Each value under it is a command-line string whose data is the full path or command used to start a program, and the system executes all such entries automatically at logon. Because entries here apply to every interactive user and require no special privileges to write in some use cases, this is a common persistence mechanism and the correct registry location to inspect for automatic startup programs.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

    Why it's wrong here

    The Winlogon registry path controls the interactive logon sequence, specifically through values such as Userinit, Shell, and VmApplet. An attacker may modify Userinit to append a malicious process to the logon chain, but this is a specialized persistence trick rather than a general-purpose startup folder. Consequently, while this key can affect startup behavior, it is not the standard 'current version Run' location that forensic analysts check first for ordinary autostart applications.

  • ✗

    HKLM\SYSTEM\CurrentControlSet\Services

    Why it's wrong here

    HKLM\SYSTEM\CurrentControlSet\Services defines Windows services and device drivers, with each subkey containing a Start value that determines whether the component is loaded at boot by the Service Control Manager. A service can certainly be configured to autostart and therefore serve as persistence, but that requires installation of a binary or kernel driver, not just adding a command-line entry to a Run key. The Services key is part of a broader autorun survey, but it is not the simple startup-program registry key named in the question.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.