CHFI Mobile and Malware Forensics Practice Question
A security analyst observes a process making repeated network connections to an IP address 192.168.1.100 on TCP port 4444, and the process writes a DLL file to C:\Users\Public\. Which THREE actions should the analyst take immediately as part of dynamic analysis?
⚠ Common exam trap
EC-Council often tests the distinction between immediate dynamic analysis actions (containment, monitoring, memory capture) versus destructive or premature remediation steps (deleting files, reimaging), and the trap here is that candidates mistakenly choose to delete the DLL or reimage the drive, thinking it will stop the malware, when in fact it destroys evidence and bypasses the forensic process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the host from the network to prevent further C2 communication
Option A is correct because the repeated TCP connections to 192.168.1.100 on port 4444 strongly indicate command-and-control (C2) traffic, and isolating the host from the network immediately contains the incident and prevents further data exfiltration or remote instructions. Option B is correct because capturing a memory dump with FTK Imager (or an equivalent tool like WinPmem or DumpIt) preserves volatile evidence such as injected code, running processes, network connections, and encryption keys that would be lost on shutdown or reboot. Option D is correct because Process Monitor (Procmon) provides real-time visibility into process creation, file system writes (such as the DLL dropped in C:\Users\Public\), registry changes, and network activity, which is essential for dynamic analysis of the malware's behavior. Option C is not appropriate because deleting the DLL destroys forensic evidence and may not stop the running process, which could simply re-drop the file; the analyst should preserve and analyze it first. Option E is not appropriate at this stage because reimaging the hard drive destroys all volatile and non-volatile evidence needed for dynamic and forensic analysis, and should only occur after evidence collection and containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate the host from the network to prevent further C2 communication
Why this is correct
Network isolation is the immediate containment step that severs the host's ability to reach the C2 infrastructure, cutting off incoming commands and blocking on-going data exfiltration. It also prevents the malware from propagating to adjacent systems via SMB, RDP, or other protocols. However, isolation must be performed in a way that preserves volatile evidence for later collection.
- ✓
Capture a memory dump using FTK Imager or similar
Why this is correct
Acquiring a memory dump with FTK Imager or a comparable tool preserves the contents of RAM, including live processes, injected code, open network sockets, and cryptographic keys in use. This volatile evidence is lost forever if the system is shut down or rebooted. Memory forensics can reveal the exact C2 commands received and any in-memory-only payloads that never touched disk.
- ✗
Delete the DLL file to stop the malware
Why it's wrong here
Deleting the DLL from disk does not terminate malware that may already have mapped its code into memory, because the running process keeps an image section in RAM. It also destroys a critical piece of evidence and could corrupt the operating system if the DLL is shared by legitimate applications. The proper order is to acquire memory and disk images first, then perform malware removal after evidence preservation.
- ✓
Monitor process creation and file system activity with Process Monitor
Why this is correct
Process Monitor's real-time instrumentation lets you observe every registry access, file creation, process spawn, and network connection the malware makes, revealing its privilege escalation, persistence, and data-collection routines. Unlike static analysis, it shows actual runtime behavior and parent-child process relationships. Capturing this telemetry supports the hypothesis that the malware is C2-connected and helps build indicators of compromise.
- ✗
Reimage the hard drive to remove the malware
Why it's wrong here
Reimaging erases the original hard drive, permanently destroying the very evidence needed to identify the malware variant, its command-and-control protocol, and the attack vector. Forensic procedures require a bit-for-bit image of the drive using a hardware write-blocker, not a destructive reinstall. Reimaging is only acceptable as a later remediation step after all forensic evidence has been collected and analyzed.
Visual reference
Go deeper
Related to this question
Learn chapter
Database Forensics: Investigating Data Breaches
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.