Courseiva

CHFI Mobile and Malware Forensics Practice Question

A security analyst discovers a suspicious registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate. The key points to a file in AppData. What is the most likely purpose of this registry key?

⚠ Common exam trap

The CHFI exam often tests the distinction between persistence mechanisms (like Run keys) and actual malware functionality; the trap here is assuming the key name 'WindowsUpdate' implies legitimate system behavior, when in fact it is a classic masquerade technique.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It ensures the malware runs every time the user logs in

The registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a standard Windows autostart location. Malware commonly adds an entry here to achieve persistence, ensuring it executes every time the user logs in. The suspicious name 'WindowsUpdate' is a common masquerade tactic to hide malicious intent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It logs the user's keystrokes

    Why it's wrong here

    The HKCU Run key does not log keystrokes; it only contains command lines that the shell executes at logon. Keystroke logging requires installing a low-level keyboard hook, injecting into processes, or using a kernel-mode filter, none of which are functions of a Run value. Therefore, while a value here can launch a keylogger, the key itself performs no logging.

  • ✓

    It ensures the malware runs every time the user logs in

    Why this is correct

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a standard per-user autostart location. When a user signs in, the Winlogon/userinit process reads every value under this key and executes the associated command line. Malware writes a value pointing to its executable in AppData so the payload is relaunched automatically on every successful login, establishing persistence.

  • ✗

    It is a legitimate Windows update configuration

    Why it's wrong here

    Windows Update configuration is stored under HKLM\SOFTWARE\Microsoft\WindowsUpdate or the policies subkeys, and legitimate update operations are handled by the Windows Update service, not by per-user Run entries. A Run value pointing to an executable in AppData is not used by Windows Update to check, download, or install updates, so this key is not a legitimate update configuration.

  • ✗

    It stores the malware's configuration settings

    Why it's wrong here

    The Run key is not a configuration-storage container; each value's data is a command line that launches a program, not static settings. Malware stores configuration data in separate registry values, files, or encrypted blobs that it reads after execution. While the malware may have configuration settings elsewhere, the Run key's sole role is to start the malware at logon, not to hold its settings.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.