CHFI Mobile and Malware Forensics Practice Question
A malware analyst is using a tool to monitor registry and file system changes during the execution of a suspicious binary. Which tool is specifically designed to take snapshots of the registry and file system before and after execution to identify changes?
⚠ Common exam trap
The CHFI exam often tests the distinction between snapshot-based comparison tools (Regshot) and real-time monitoring tools (Process Monitor), leading candidates to confuse Process Monitor's live logging capability with the before-and-after snapshot functionality required by the question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regshot
Regshot is a lightweight open-source tool designed specifically to compare registry hives and file system snapshots taken before and after executing a binary. It generates a detailed report of added, modified, or deleted keys and files, making it ideal for malware analysis to quickly identify persistence mechanisms or configuration changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Regshot
Why this is correct
Regshot is a lightweight open-source utility that captures a baseline snapshot of the Windows registry and, optionally, the file system, then produces a second snapshot after the malware is executed. It compares the two snapshots and generates a detailed diff report, making it ideal for quickly identifying persistence locations, new files, and altered keys. Because it is not a real-time logger, it does not overwhelm the analyst with noise; instead, it gives a clean before-and-after view of system changes.
- ✗
Cuckoo Sandbox
Why it's wrong here
Cuckoo Sandbox is an automated dynamic malware analysis platform that executes a suspicious file inside an isolated virtual machine and compiles a rich behavioral report, including API calls, network traffic, and filesystem and registry interactions. Its monitoring relies on hooks and kernel drivers that capture events in real time rather than taking static before/after snapshots, and it is typically used as a whole-sandbox solution rather than a direct comparison tool. Therefore, while it can reveal malicious activity, it does not match the description of a tool specifically built for taking registry and file system snapshots.
- ✗
Process Explorer
Why it's wrong here
Process Explorer is a Sysinternals utility that provides an advanced, live view of running processes, their parent-child relationships, loaded DLLs, and open handles. It does not create registry or file system snapshots or perform before/after comparisons; instead, it shows the current state of objects in memory and can identify which process has a file or registry key open. This makes it a powerful diagnostic tool for live systems but not a change-tracking snapshot utility.
- ✗
Process Monitor
Why it's wrong here
Process Monitor is a real-time monitoring tool from Sysinternals that logs every registry, file system, network, and process/thread operation as it occurs, complete with timestamps and process details. It operates continuously by intercepting system calls, so it is not designed to compare a 'before' state to an 'after' state the way Regshot does. While it can be used in malware analysis to observe transient events and dependencies, it does not provide a simplified summary of changes because it captures vast amounts of raw data rather than a snapshot diff.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.