CHFI Mobile and Malware Forensics Practice Question
A malware analyst is performing static analysis on a suspicious PE file. Which TWO of the following are examples of anti-forensic techniques that the malware might use to hinder analysis? (Select TWO.)
⚠ Common exam trap
EC-Council often tests the distinction between anti-forensic techniques (which actively hinder analysis) and common malware behaviors (which are forensic artifacts themselves), so candidates mistakenly select persistence or file-writing options as anti-forensic when they are actually evidence-creating actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Packing or obfuscating the malicious code
Option B is correct because packing or obfuscating the malicious code (e.g., with UPX, Themida, or custom crypter) hides the true code and strings from static analysis tools, forcing the analyst to unpack or emulate before meaningful inspection is possible. Option E is correct because timestomping deliberately alters a file's $STANDARD_INFORMATION and/or $FILE_NAME timestamps (creation, modification, access, MFT entry change) to mislead investigators about when the malware was placed or executed, which is a classic anti-forensic technique. Option A is not an anti-forensic technique against static analysis; TLS is simply an encrypted transport that hinders network traffic inspection, not examination of the PE file itself. Option C is a persistence mechanism (e.g., Run keys, Services), not an anti-forensic measure. Option D is normal runtime behavior for many programs and does not specifically hinder static analysis of the PE file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using TLS encryption for network communication
Why it's wrong here
Using TLS encryption for network communication is a standard security measure that protects the confidentiality of data in transit, not an anti-forensic technique. It does not hide the fact that network communication occurred, nor does it obscure the endpoints or the timing of the connection, which are often the key forensic artifacts. In fact, TLS traffic can be logged and analyzed, and non-encrypted traffic may even be easier for defenders to inspect, so this choice does not actively hinder forensic investigation.
- ✓
Packing or obfuscating the malicious code
Why this is correct
Packing or obfuscating the malicious code is a core anti-forensic technique because it compresses, encrypts, or otherwise transforms the executable's original machine code, rendering it opaque to static signature-based detection and manual reverse engineering. The malware's true payload is only revealed at runtime when it unpacks itself in memory, forcing analysts to use dynamic analysis or memory forensics. This deliberate obfuscation directly impedes the malware analyst's ability to inspect the code, making it the correct answer.
- ✗
Creating registry keys for persistence
Why it's wrong here
Creating registry keys for persistence is a functional capability that ensures the malware survives reboots or user logons, but it is not an anti-forensic technique. Registry modifications leave behind identifiable artifacts that are commonly extracted by forensic tools, and the presence of an unexpected Run key or service entry often serves as a strong indicator of compromise. Rather than hiding evidence, persistence creates additional traces that an analyst can leverage for detection and attribution.
- ✗
Writing temporary files to the %TEMP% directory
Why it's wrong here
Writing temporary files to the %TEMP% directory is a common runtime behavior exhibited by both benign software and malware, so by itself it does not constitute anti-forensics. Malware may use temp files for staging, but this activity generates filesystem artifacts that can be recovered and analyzed, rather than actively concealing forensic evidence. It lacks the deliberate intent to deceive or hinder forensic tools, which distinguishes true anti-forensic techniques from mundane execution details.
- ✓
Timestomping to modify file creation and modification timestamps
Why this is correct
Timestomping is a well-known anti-forensic technique that deliberately alters the creation, modification, and access timestamps (MAC times) of files to obscure when they were created, accessed, or modified. By manipulating these metadata values, the malware analyst's timeline analysis is corrupted, making it difficult to reconstruct the sequence of events or link the malicious file to a specific incident. This activity is specifically designed to mislead forensic investigation, so it is a correct answer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.