CHFI Mobile and Malware Forensics Practice Question
A security analyst runs the command `regshot64.exe compare` after executing malware. Regshot reports that the following registry key was created: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate`. Which conclusion is MOST likely?
⚠ Common exam trap
The CHFI exam often tests the distinction between persistence mechanisms (like Run keys) and other malware behaviors (like encryption or network changes), trapping candidates who assume any registry change indicates data destruction or system modification rather than survival.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The malware installed a persistence mechanism
The registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate` is a standard Windows Run key, which automatically executes the specified program at user logon. By creating this key, the malware ensures it runs every time the user logs in, establishing persistence. This is a classic persistence mechanism, not an action related to encryption, file deletion, or network changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The malware encrypted the user's documents
Why it's wrong here
Regshot's comparison is limited to the Windows registry; it does not scan or compare filesystem contents. Encryption of a user's documents would manifest as changes in file data, extensions, or MFT entries, none of which are represented in the registry. Thus, a regshot64.exe compare report cannot contain evidence of document encryption, making this conclusion unsupported by the tool's output.
- ✓
The malware installed a persistence mechanism
Why this is correct
A persistence mechanism is commonly implemented by creating a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or the corresponding HKLM key. When regshot64.exe compare shows a new 'Run' value pointing to a suspicious executable, that is direct evidence the malware installed an auto-start mechanism. Registry modifications of this type are exactly what regshot is designed to detect, so this is the correct conclusion.
- ✗
The malware deleted a system file
Why it's wrong here
Deleting a system file, such as a DLL in System32, is a filesystem operation and would not appear in a registry-only diff. Even if the deletion indirectly caused a registry update, such as removing a service entry, the primary behavior is file removal, not a registry change. Regshot64.exe compare only compares registry snapshots, so it cannot provide evidence for system file deletion; filesystem monitoring tools would be needed to support that claim.
- ✗
The malware modified a network configuration
Why it's wrong here
Network configuration changes are stored in specific registry paths, such as HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters and its interfaces. The provided finding indicates no changes were observed under those network-related keys, so asserting that the malware altered network configuration is unsupported by the evidence. A conclusion about network modification would require seeing relevant key changes in the regshot diff, which are absent here.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.