Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensics examiner finds a suspicious entry in the Windows Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to a PowerShell command. Which persistence mechanism does this represent, and what is the MOST likely impact?

⚠ Common exam trap

EC-Council often tests the distinction between user-level (HKCU) and machine-level (HKLM) Run keys, and candidates mistakenly associate any registry entry with service persistence or scheduled tasks due to overlapping persistence concepts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Registry run key persistence; the command executes each time the user logs in.

The HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key is a standard Windows Run key that automatically executes programs when the user logs in. A PowerShell command placed here will run with the user's privileges at each interactive logon, establishing persistence without requiring elevated privileges or system-level access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Registry run key persistence; the command executes each time the user logs in.

    Why this is correct

    HKCU\...\CurrentVersion\Run entries are per-user autostart locations. Windows reads them at logon and launches the referenced command, so the PowerShell payload executes each time that user signs in, giving the attacker persistent code execution without administrative rights.

  • ✗

    Service persistence; the malware runs as a system service.

    Why it's wrong here

    Run key entries launch in the user's context at logon, not as system services; services persist under the Services registry hive or SCM. It is tempting because services provide durable system-level persistence, but a HKCU Run value cannot register a service.

  • ✗

    Scheduled task persistence; the command runs at a scheduled time.

    Why it's wrong here

    Run key values execute immediately at user logon, not at a scheduled time; scheduled tasks persist via Task Scheduler entries. It is tempting because both achieve recurring execution, but the Run key is logon-triggered, so no schedule exists to match.

  • ✗

    Bootkit persistence; the malware loads before the OS.

    Why it's wrong here

    A Run key entry executes within the logged-on user's session after logon, not before the operating system loads; bootkits infect boot sectors or firmware. It is tempting because bootkits are high-impact persistence, but they require boot-level infection, not a registry Run value.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.