CHFI Mobile and Malware Forensics Practice Question
A malware analyst runs a suspicious executable in Cuckoo Sandbox. The report shows that the process created a mutex named 'Global\MyMalwareMutex'. What is the significance of this mutex?
⚠ Common exam trap
EC-Council often tests the misconception that any named object with 'Global' implies network or cross-system communication, but in Windows, 'Global\' simply refers to the kernel object namespace accessible to all sessions on the same machine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It prevents multiple instances of the malware from running simultaneously
The mutex named 'Global\MyMalwareMutex' is a named synchronization object used by the malware to ensure only one instance of its process runs at a time. This prevents conflicts in operations like file writing or network communication that could occur if multiple copies executed simultaneously. In Cuckoo Sandbox, detecting such a mutex is a common indicator of single-instance malware behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is used to communicate with a remote command and control server
Why it's wrong here
A mutex is a kernel synchronization primitive that coordinates thread access to shared resources within a single host; it has no network stack interface and cannot establish outbound connections or receive commands. Command-and-control communication relies on sockets, HTTP(S), DNS, or other protocol handlers, not on mutual-exclusion objects. Therefore, detecting a mutex in Cuckoo does not indicate C2 activity, though malware families often create one alongside their C2 setup for unrelated single-instance enforcement.
- ✓
It prevents multiple instances of the malware from running simultaneously
Why this is correct
This is the correct interpretation: when a process creates a named mutex and then checks for its existence before proceeding, it is using the object as a global, system-wide flag. If the mutex already exists, the malware terminates itself or exits its main thread, ensuring that only one copy of the malware is active at any time. Analysts see this in Cuckoo sandbox when the sample creates a uniquely named mutex and later attempts to open the same mutex again; this behavior prevents duplicate infections, avoids file-corruption conflicts, and preserves the integrity of the malware's own state.
- ✗
It indicates the malware is packed with UPX
Why it's wrong here
UPX packing is an executable-compression technique that transforms the original Portable Executable (PE) file into a smaller self-decompressing stub; the presence of a mutex string is unrelated to the packing algorithm. Cuckoo's PE analysis reports entropy, section names (e.g., UPX0/UPX1), and import-table anomalies to identify UPX, not by observing mutexes. A packed binary can create a mutex, and an unpacked binary can too, so mutex names provide no evidence of whether UPX was used.
- ✗
It stores encrypted configuration data
Why it's wrong here
A mutex is not a storage container; it carries no data payload beyond a small kernel object with a name and a security descriptor. Encrypted configuration data is normally stored in a file, the registry, a binary section, or an environment variable, then read and decrypted in memory at runtime. When Cuckoo reports a mutex, it is merely capturing a named synchronization handle — it cannot hold the malware's configuration, encrypted or otherwise, so this option reflects a confusion between data objects and synchronization objects.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.