Courseiva

CHFI Mobile and Malware Forensics Practice Question

A security analyst observes a process making repeated network connections to an IP address 192.168.1.100 on TCP port 4444, and the process writes a DLL file to C:\Users\Public\. Which THREE actions should the analyst take immediately as part of dynamic analysis?

⚠ Common exam trap

EC-Council often tests the distinction between immediate dynamic analysis actions (containment, monitoring, memory capture) versus destructive or premature remediation steps (deleting files, reimaging), and the trap here is that candidates mistakenly choose to delete the DLL or reimage the drive, thinking it will stop the malware, when in fact it destroys evidence and bypasses the forensic process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the host from the network to prevent further C2 communication

Option A is correct because the repeated TCP connections to 192.168.1.100 on port 4444 strongly indicate command-and-control (C2) traffic, and isolating the host from the network immediately contains the incident and prevents further data exfiltration or remote instructions. Option B is correct because capturing a memory dump with FTK Imager (or an equivalent tool like WinPmem or DumpIt) preserves volatile evidence such as injected code, running processes, network connections, and encryption keys that would be lost on shutdown or reboot. Option D is correct because Process Monitor (Procmon) provides real-time visibility into process creation, file system writes (such as the DLL dropped in C:\Users\Public\), registry changes, and network activity, which is essential for dynamic analysis of the malware's behavior. Option C is not appropriate because deleting the DLL destroys forensic evidence and may not stop the running process, which could simply re-drop the file; the analyst should preserve and analyze it first. Option E is not appropriate at this stage because reimaging the hard drive destroys all volatile and non-volatile evidence needed for dynamic and forensic analysis, and should only occur after evidence collection and containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Isolate the host from the network to prevent further C2 communication

    Why this is correct

    Network isolation is the immediate containment step that severs the host's ability to reach the C2 infrastructure, cutting off incoming commands and blocking on-going data exfiltration. It also prevents the malware from propagating to adjacent systems via SMB, RDP, or other protocols. However, isolation must be performed in a way that preserves volatile evidence for later collection.

  • ✓

    Capture a memory dump using FTK Imager or similar

    Why this is correct

    Acquiring a memory dump with FTK Imager or a comparable tool preserves the contents of RAM, including live processes, injected code, open network sockets, and cryptographic keys in use. This volatile evidence is lost forever if the system is shut down or rebooted. Memory forensics can reveal the exact C2 commands received and any in-memory-only payloads that never touched disk.

  • ✗

    Delete the DLL file to stop the malware

    Why it's wrong here

    Deleting the DLL from disk does not terminate malware that may already have mapped its code into memory, because the running process keeps an image section in RAM. It also destroys a critical piece of evidence and could corrupt the operating system if the DLL is shared by legitimate applications. The proper order is to acquire memory and disk images first, then perform malware removal after evidence preservation.

  • ✓

    Monitor process creation and file system activity with Process Monitor

    Why this is correct

    Process Monitor's real-time instrumentation lets you observe every registry access, file creation, process spawn, and network connection the malware makes, revealing its privilege escalation, persistence, and data-collection routines. Unlike static analysis, it shows actual runtime behavior and parent-child process relationships. Capturing this telemetry supports the hypothesis that the malware is C2-connected and helps build indicators of compromise.

  • ✗

    Reimage the hard drive to remove the malware

    Why it's wrong here

    Reimaging erases the original hard drive, permanently destroying the very evidence needed to identify the malware variant, its command-and-control protocol, and the attack vector. Forensic procedures require a bit-for-bit image of the drive using a hardware write-blocker, not a destructive reinstall. Reimaging is only acceptable as a later remediation step after all forensic evidence has been collected and analyzed.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Go deeper

Related to this question

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.