Courseiva

CHFI Mobile and Malware Forensics Practice Question

A malware analyst is performing static analysis on a suspicious PE file. Which TWO of the following are examples of anti-forensic techniques that the malware might use to hinder analysis? (Select TWO.)

⚠ Common exam trap

EC-Council often tests the distinction between anti-forensic techniques (which actively hinder analysis) and common malware behaviors (which are forensic artifacts themselves), so candidates mistakenly select persistence or file-writing options as anti-forensic when they are actually evidence-creating actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Packing or obfuscating the malicious code

Option B is correct because packing or obfuscating the malicious code (e.g., with UPX, Themida, or custom crypter) hides the true code and strings from static analysis tools, forcing the analyst to unpack or emulate before meaningful inspection is possible. Option E is correct because timestomping deliberately alters a file's $STANDARD_INFORMATION and/or $FILE_NAME timestamps (creation, modification, access, MFT entry change) to mislead investigators about when the malware was placed or executed, which is a classic anti-forensic technique. Option A is not an anti-forensic technique against static analysis; TLS is simply an encrypted transport that hinders network traffic inspection, not examination of the PE file itself. Option C is a persistence mechanism (e.g., Run keys, Services), not an anti-forensic measure. Option D is normal runtime behavior for many programs and does not specifically hinder static analysis of the PE file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using TLS encryption for network communication

    Why it's wrong here

    Using TLS encryption for network communication is a standard security measure that protects the confidentiality of data in transit, not an anti-forensic technique. It does not hide the fact that network communication occurred, nor does it obscure the endpoints or the timing of the connection, which are often the key forensic artifacts. In fact, TLS traffic can be logged and analyzed, and non-encrypted traffic may even be easier for defenders to inspect, so this choice does not actively hinder forensic investigation.

  • ✓

    Packing or obfuscating the malicious code

    Why this is correct

    Packing or obfuscating the malicious code is a core anti-forensic technique because it compresses, encrypts, or otherwise transforms the executable's original machine code, rendering it opaque to static signature-based detection and manual reverse engineering. The malware's true payload is only revealed at runtime when it unpacks itself in memory, forcing analysts to use dynamic analysis or memory forensics. This deliberate obfuscation directly impedes the malware analyst's ability to inspect the code, making it the correct answer.

  • ✗

    Creating registry keys for persistence

    Why it's wrong here

    Creating registry keys for persistence is a functional capability that ensures the malware survives reboots or user logons, but it is not an anti-forensic technique. Registry modifications leave behind identifiable artifacts that are commonly extracted by forensic tools, and the presence of an unexpected Run key or service entry often serves as a strong indicator of compromise. Rather than hiding evidence, persistence creates additional traces that an analyst can leverage for detection and attribution.

  • ✗

    Writing temporary files to the %TEMP% directory

    Why it's wrong here

    Writing temporary files to the %TEMP% directory is a common runtime behavior exhibited by both benign software and malware, so by itself it does not constitute anti-forensics. Malware may use temp files for staging, but this activity generates filesystem artifacts that can be recovered and analyzed, rather than actively concealing forensic evidence. It lacks the deliberate intent to deceive or hinder forensic tools, which distinguishes true anti-forensic techniques from mundane execution details.

  • ✓

    Timestomping to modify file creation and modification timestamps

    Why this is correct

    Timestomping is a well-known anti-forensic technique that deliberately alters the creation, modification, and access timestamps (MAC times) of files to obscure when they were created, accessed, or modified. By manipulating these metadata values, the malware analyst's timeline analysis is corrupted, making it difficult to reconstruct the sequence of events or link the malicious file to a specific incident. This activity is specifically designed to mislead forensic investigation, so it is a correct answer.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.