CHFI Mobile and Malware Forensics Practice Question
A security analyst notices a process named 'svchost.exe' running from the directory 'C:\Users\Public\svchost.exe'. This is suspicious because legitimate svchost.exe runs from 'C:\Windows\System32'. What type of indicator is this?
⚠ Common exam trap
EC-Council often tests the distinction between static indicators (file hash, registry key) and dynamic indicators (behavioral, network), and the trap here is that candidates confuse a file path anomaly with a network or registry indicator because they associate svchost.exe with system-level activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Behavioural indicator
B is correct because the presence of svchost.exe in C:\Users\Public\ instead of C:\Windows\System32 indicates a deviation from the expected execution path, which is a classic behavioral indicator. Behavioral indicators focus on anomalous actions or file placements rather than static attributes like hashes or network traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network indicator
Why it's wrong here
A network indicator specifically refers to artifacts such as command-and-control IP addresses, domains, URLs, or network traffic signatures that tie a host to external malicious infrastructure. In this scenario, the observation is a process name and its execution path, which are local host-based attributes, not a network connection or external endpoint. Therefore, classifying svchost.exe's anomalous path as a network indicator mischaracterizes the IOC type.
- ✓
Behavioural indicator
Why this is correct
The correct classification is a behavioral indicator because the security analyst is observing an execution pattern—svchost.exe running from a path other than its legitimate C:\Windows\System32 location. Behavioral indicators focus on deviations from known-good baseline activities, such as unusual process paths, command-line arguments, or parent-child process relationships. This process's anomalous path is a classic sign of masquerading or binary planting, making it a host-based behavioral red flag.
- ✗
File hash indicator
Why it's wrong here
A file hash indicator would be a cryptographic digest (e.g., MD5, SHA-1, SHA-256) computed from the binary's exact content, used to uniquely identify known malware samples via threat intelligence feeds. The analyst noted a process name and its execution path, not a hash value, so there is no basis for associating this observation with a file hash indicator. Additionally, the same svchost.exe binary may have a legitimate hash when clean, further distinguishing this IOC type from the observed behavioral anomaly.
- ✗
Registry key indicator
Why it's wrong here
A registry key indicator relates to persistence, configuration, or autostart mechanisms stored in Windows Registry hives, such as HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. The observed anomaly involves the execution of a process from an unexpected path, which is an on-disk and runtime behavior, not a registry entry. Although attackers often use registry keys to launch malicious processes, the evidence described here does not include any registry modification, so it cannot be classified as a registry indicator.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.