Courseiva

CHFI Mobile and Malware Forensics Practice Question

A security analyst notices a process named 'svchost.exe' running from the directory 'C:\Users\Public\svchost.exe'. This is suspicious because legitimate svchost.exe runs from 'C:\Windows\System32'. What type of indicator is this?

⚠ Common exam trap

EC-Council often tests the distinction between static indicators (file hash, registry key) and dynamic indicators (behavioral, network), and the trap here is that candidates confuse a file path anomaly with a network or registry indicator because they associate svchost.exe with system-level activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Behavioural indicator

B is correct because the presence of svchost.exe in C:\Users\Public\ instead of C:\Windows\System32 indicates a deviation from the expected execution path, which is a classic behavioral indicator. Behavioral indicators focus on anomalous actions or file placements rather than static attributes like hashes or network traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network indicator

    Why it's wrong here

    A network indicator specifically refers to artifacts such as command-and-control IP addresses, domains, URLs, or network traffic signatures that tie a host to external malicious infrastructure. In this scenario, the observation is a process name and its execution path, which are local host-based attributes, not a network connection or external endpoint. Therefore, classifying svchost.exe's anomalous path as a network indicator mischaracterizes the IOC type.

  • ✓

    Behavioural indicator

    Why this is correct

    The correct classification is a behavioral indicator because the security analyst is observing an execution pattern—svchost.exe running from a path other than its legitimate C:\Windows\System32 location. Behavioral indicators focus on deviations from known-good baseline activities, such as unusual process paths, command-line arguments, or parent-child process relationships. This process's anomalous path is a classic sign of masquerading or binary planting, making it a host-based behavioral red flag.

  • ✗

    File hash indicator

    Why it's wrong here

    A file hash indicator would be a cryptographic digest (e.g., MD5, SHA-1, SHA-256) computed from the binary's exact content, used to uniquely identify known malware samples via threat intelligence feeds. The analyst noted a process name and its execution path, not a hash value, so there is no basis for associating this observation with a file hash indicator. Additionally, the same svchost.exe binary may have a legitimate hash when clean, further distinguishing this IOC type from the observed behavioral anomaly.

  • ✗

    Registry key indicator

    Why it's wrong here

    A registry key indicator relates to persistence, configuration, or autostart mechanisms stored in Windows Registry hives, such as HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. The observed anomaly involves the execution of a process from an unexpected path, which is an on-disk and runtime behavior, not a registry entry. Although attackers often use registry keys to launch malicious processes, the evidence described here does not include any registry modification, so it cannot be classified as a registry indicator.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.