Courseiva

CHFI Mobile and Malware Forensics Practice Question

A security analyst runs the command `regshot64.exe compare` after executing malware. Regshot reports that the following registry key was created: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate`. Which conclusion is MOST likely?

⚠ Common exam trap

The CHFI exam often tests the distinction between persistence mechanisms (like Run keys) and other malware behaviors (like encryption or network changes), trapping candidates who assume any registry change indicates data destruction or system modification rather than survival.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The malware installed a persistence mechanism

The registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SecureUpdate` is a standard Windows Run key, which automatically executes the specified program at user logon. By creating this key, the malware ensures it runs every time the user logs in, establishing persistence. This is a classic persistence mechanism, not an action related to encryption, file deletion, or network changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The malware encrypted the user's documents

    Why it's wrong here

    Regshot's comparison is limited to the Windows registry; it does not scan or compare filesystem contents. Encryption of a user's documents would manifest as changes in file data, extensions, or MFT entries, none of which are represented in the registry. Thus, a regshot64.exe compare report cannot contain evidence of document encryption, making this conclusion unsupported by the tool's output.

  • ✓

    The malware installed a persistence mechanism

    Why this is correct

    A persistence mechanism is commonly implemented by creating a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or the corresponding HKLM key. When regshot64.exe compare shows a new 'Run' value pointing to a suspicious executable, that is direct evidence the malware installed an auto-start mechanism. Registry modifications of this type are exactly what regshot is designed to detect, so this is the correct conclusion.

  • ✗

    The malware deleted a system file

    Why it's wrong here

    Deleting a system file, such as a DLL in System32, is a filesystem operation and would not appear in a registry-only diff. Even if the deletion indirectly caused a registry update, such as removing a service entry, the primary behavior is file removal, not a registry change. Regshot64.exe compare only compares registry snapshots, so it cannot provide evidence for system file deletion; filesystem monitoring tools would be needed to support that claim.

  • ✗

    The malware modified a network configuration

    Why it's wrong here

    Network configuration changes are stored in specific registry paths, such as HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters and its interfaces. The provided finding indicates no changes were observed under those network-related keys, so asserting that the malware altered network configuration is unsupported by the evidence. A conclusion about network modification would require seeing relevant key changes in the regshot diff, which are absent here.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.