Courseiva

CHFI Mobile and Malware Forensics Practice Question

A security analyst suspects a mobile device is infected with malware that exfiltrates data via DNS queries. Which tool or technique would be MOST effective for detecting this behavior during dynamic analysis?

⚠ Common exam trap

EC-Council often tests the misconception that dynamic analysis of malware behavior requires host-based monitoring (like Process Monitor) rather than network-based analysis, but for data exfiltration via DNS, packet capture is essential.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wireshark to capture and analyze network packets for anomalous DNS queries

D is correct because DNS exfiltration involves encoding stolen data into DNS query fields (e.g., subdomains or TXT records) and sending them to a malicious server. Wireshark captures and analyzes raw network packets, allowing the analyst to inspect DNS query payloads for anomalous patterns such as unusually long hostnames, high query volume, or queries to suspicious domains, which are hallmarks of DNS tunneling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PEiD to detect packers in the mobile app binary

    Why it's wrong here

    PEiD is a Windows Portable Executable analysis utility that identifies packers and compilers by scanning PE headers. A mobile app's Android APK consists of DEX bytecode inside a ZIP container, while iOS apps are Mach-O binaries, so PEiD cannot even parse the binary. It also performs zero network analysis, so it cannot reveal DNS anomalies.

  • ✗

    Regshot to compare registry snapshots before and after execution

    Why it's wrong here

    Regshot is a Windows tool that compares snapshots of the Registry and file system before and after a program executes, which is useful for classic Windows malware install-time changes. Mobile platforms do not have a Windows registry hive — Android uses SharedPreferences and XML/SQLite stores, and iOS uses plist-backed preferences — so Regshot has no relevant state to compare. It cannot capture on-device DNS traffic either.

  • ✗

    Process Monitor to observe registry and file system changes

    Why it's wrong here

    Process Monitor (Procmon) logs Windows process/thread activity, Registry access, and file I/O via kernel callbacks, but its visibility is limited to the local Windows system call interface and it does not perform raw packet capture or DNS protocol dissection. It cannot be installed on an Android or iOS handset to monitor app behavior, and even on Windows it would not reveal a domain-generation-algorithm lookup happening over Wi-Fi. The alert is network-centric; Procmon only addresses system-level state, not upstream traffic.

  • ✓

    Wireshark to capture and analyze network packets for anomalous DNS queries

    Why this is correct

    Wireshark is a packet analyzer that captures raw frames and reassembles DNS messages, letting an analyst filter for dns.qry.name, spot repeated NXDOMAIN responses, or identify DGA subdomains typical of mobile malware. On Android, remote capture via USB tethering or a dedicated access point gives visibility into all app DNS lookups without modifying the device. Correlating query timing and volume can confirm an infection when static analysis is inconclusive.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.