Courseiva

CHFI Mobile and Malware Forensics Practice Question

A security analyst runs a dynamic analysis of a suspected malware sample using Cuckoo Sandbox. The report shows that the sample created a mutex named 'Global\MyMaliciousMutex', added a registry run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and attempted to communicate with an IP address 185.10.68.12 on port 443. Which of the following is the BEST immediate indicator of compromise (IoC) to share with the threat intelligence team?

⚠ Common exam trap

The CHFI exam often tests the concept that network-based IoCs (IP addresses, domains) are considered more immediate and actionable for threat intelligence sharing than host-based artifacts (mutexes, registry keys) because they enable perimeter defense and are less dependent on specific file hashes that change with each variant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IP address 185.10.68.12

The IP address 185.10.68.12 on port 443 is the best immediate indicator of compromise (IoC) because it is a network-based artifact that can be directly blocked at the firewall or monitored for outbound connections. Network-based IoCs are often prioritized in threat intelligence sharing because they enable proactive perimeter defense and are actionable across multiple systems, unlike host-based artifacts (mutexes, registry keys) that require endpoint-level detection. Additionally, the IP address is independent of file hashes and can be used to detect or block communications even when the malware binary changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The registry run key location

    Why it's wrong here

    The registry run key location indicates a persistence mechanism that allows the malware to launch automatically on startup. However, this local artifact only helps with host-based detection and cleanup; it does not prevent the malware from communicating with its command-and-control server. An attacker can easily change the run key or use other persistence methods, making it a weak indicator for immediate network containment. The C2 IP address is far more actionable because it can be blocked at the egress firewall.

  • ✗

    The sample's MD5 hash

    Why it's wrong here

    The MD5 hash uniquely fingerprints this exact malware binary, which is valuable for searching threat intelligence feeds and detecting identical samples across endpoints. Yet from a dynamic analysis perspective, the hash reveals nothing about the malware's current network behavior, so it cannot be used to interrupt communication. Additionally, an MD5 hash is trivially changed by recompiling the binary, so it is not a stable target for blocking. The immediate response should focus on the observed C2 IP to sever the active channel.

  • ✓

    The IP address 185.10.68.12

    Why this is correct

    The IP address 185.10.68.12 is the command-and-control endpoint that the malware dials out to, so it is the most immediately actionable indicator for containment. An analyst can block this IP at the firewall or proxy, add it to a threat intelligence feed, and alert on any matching egress traffic. This directly severs the malware's ability to receive commands or exfiltrate data, unlike host-based artifacts. In a live engagement, isolating this network indicator is a critical first step before deeper host remediation.

  • ✗

    The mutex name 'Global\MyMaliciousMutex'

    Why it's wrong here

    The mutex 'Global\MyMaliciousMutex' is a synchronization object the malware creates to ensure only one copy runs, and its name can aid in threat hunting on infected hosts. However, detecting the mutex requires already having visibility into the host, and it does not stop the malware from communicating with its C2 server. Mutex names are also frequently randomized or per-sample, making them unreliable for network-level blocking. A firewall rule against the C2 IP is a direct and universal mitigation, whereas mutex detection is only a local signal.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.