Courseiva

CHFI Mobile and Malware Forensics Practice Question

A malware analyst is performing dynamic analysis of a suspected trojan in a sandbox environment. Which of the following behaviours are strong indicators that the malware is establishing persistence on the infected system? (Select THREE.)

⚠ Common exam trap

EC-Council often tests the distinction between persistence mechanisms and other malware behaviors (like network communication or inter-process synchronization), so the trap here is confusing network activity (C) or mutex creation (E) with persistence, when only startup-modifying actions (A, B, D) qualify.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Creating a scheduled task that runs at system startup

Option A is correct because creating a scheduled task configured to trigger at system startup (e.g., via schtasks or the Task Scheduler COM API with a boot/logon trigger) is a classic persistence mechanism that ensures the trojan executes automatically after reboots. Option B is correct because registering a Windows service (e.g., through CreateService or sc.exe) allows the malware to be launched by the Service Control Manager at boot, providing durable, privileged persistence. Option D is correct because writing a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run causes the referenced executable to be launched automatically at user logon, a well-known autostart persistence location. Option C is not a persistence indicator; an outbound connection to port 443 typically reflects command-and-control or exfiltration activity, not survival across reboots. Option E is not a persistence indicator either; creating a named mutex such as Global\MyMutex is commonly used for single-instance enforcement or anti-analysis/anti-sandbox checks, not for maintaining execution on the host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Creating a scheduled task that runs at system startup

    Why this is correct

    Scheduled tasks provide persistence by registering a trigger that activates the malware at system startup, before any user logs on. Using tools like schtasks.exe or by dropping an XML task into C:\Windows\System32\Tasks, an attacker can run arbitrary code with SYSTEM privileges on every boot. Because the task is stored on disk and loaded by the Task Scheduler service, it satisfies the definition of an auto-start extension point (ASEP) and is a common persistence mechanism.

  • ✓

    Creating a Windows service named 'UpdateService'

    Why this is correct

    Creating a Windows service named 'UpdateService' achieves persistence because the Service Control Manager (SCM) automatically starts services configured with SERVICE_AUTO_START when the operating system boots. The service binary can be installed via the CreateService API or sc.exe and may run as LocalSystem, granting elevated privileges. By choosing a benign-sounding name, the attacker blends the service with legitimate update components, making manual detection more difficult.

  • ✗

    Connecting to an IP address on port 443

    Why it's wrong here

    Connecting to an IP address on port 443 is an indicator of command-and-control (C2) communication or data exfiltration, not persistence. An outbound TLS connection provides a live communication channel, but it does not cause the malware to re-execute after a reboot or logon. Persistence mechanisms are specifically designed to relaunch the payload at startup or logon, whereas a network connection is a transient runtime behavior.

  • ✓

    Writing a value to HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    Why this is correct

    The HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key is a classic persistence location because the Winlogon process reads it at user logon and executes each listed command. Because it is under the HKCU hive, the malware does not require administrative privileges to write there, making it attractive for initial footholds. Attackers often obfuscate the command value with a script or PowerShell encoded payload to evade static analysis.

  • ✗

    Creating a mutex named 'Global\MyMutex'

    Why it's wrong here

    Creating a mutex named 'Global\MyMutex' is a synchronization primitive used to ensure that only one instance of the malware runs at a time. This is important for avoiding multiple simultaneous infections or conflicting worker processes, but it does not provide any mechanism to launch the malware automatically after reboot. A mutex exists only in kernel memory during runtime and is not a file, registry entry, or scheduled task, so it cannot serve as a persistence mechanism.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.