CHFI Mobile and Malware Forensics Practice Question
A security team is investigating a suspected Advanced Persistent Threat (APT) intrusion. They have identified several IoCs. Which THREE of the following are considered standard types of Indicators of Compromise?
⚠ Common exam trap
EC-Council often tests the distinction between technical IoCs (like IP addresses, hashes, registry keys) and non-technical or variable indicators (like employee IDs or email subject lines), trapping candidates who confuse phishing campaign metadata with standard forensic IoCs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP address of a command and control server
Option B is correct because the IP address of a command and control (C2) server is a classic network-based IoC that defenders use to detect beaconing or outbound connections to attacker infrastructure. Option C is correct because an MD5 hash of a malicious executable is a file-based (hash) IoC that uniquely identifies known malware samples and enables blocklisting or scanning. Option D is correct because a registry key path used for persistence is a host-based IoC, since attackers commonly abuse Run keys, Services, or similar registry locations to survive reboots. Option A is not a standard IoC type because employee badge numbers are identity/HR data, not technical artifacts of compromise. Option E is not a standard IoC type because an email subject line is contextual phishing content, not a reliable technical indicator such as a hash, IP, domain, URL, or registry artifact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Employee badge number
Why it's wrong here
Employee badge numbers are administrative identifiers tied to physical access and human resources records, not technical artifacts generated by a compromise. IoCs are observable forensic evidence such as network addresses, file hashes, or registry changes that directly indicate malicious activity on a system. While a badge number could be relevant in an insider threat investigation, it cannot be used in the same automated, signature-based detection workflows that define indicator-of-compromise analysis.
- ✓
IP address of a command and control server
Why this is correct
An IP address for a command and control (C2) server is a standard network-based IoC because it identifies the remote host a compromised endpoint contacts to receive instructions or exfiltrate data. Analysts frequently cross-reference such addresses with threat intelligence feeds that map them to known malware families, botnets, or ongoing campaigns, then create firewall rules, IDS alerts, or sinkhole entries. However, a single IP may be rotated quickly or sit behind a CDN, so robust detection typically correlates it with domains, certificates, or JA3 hashes.
- ✓
MD5 hash of a malicious executable
Why this is correct
An MD5 hash of a malicious executable is a file-based IoC that uniquely fingerprints the binary's exact byte content, enabling defenders to scan endpoint files and match them against known malware samples in databases or sandbox outputs. Despite MD5's established collision vulnerabilities, it remains prevalent in legacy threat-intel feeds and is often supplemented by SHA256 for stronger integrity. This indicator proves most valuable during incident response for identifying the same malicious variant across multiple affected hosts, even if the filename or location varies.
- ✓
Registry key path used for persistence
Why this is correct
A registry key path used for persistence is a host-based IoC that exposes where an attacker has installed an autorun entry, such as Run or RunOnce keys, to launch malicious code automatically at boot or user login. Mapping this path to MITRE ATT&CK techniques like T1547.001 helps investigators understand the privilege level required and the process responsible for creating the entry. This indicator is operationally crucial because it guides the responder to the exact location that must be cleaned to break persistence during remediation.
- ✗
Email subject line from a phishing campaign
Why it's wrong here
An email subject line from a phishing campaign is not a standard IoC; it is more accurately an indicator of attack (IoA) or a TTP because it describes the social engineering lure rather than a technical artifact left on an endpoint or in network communication. Although security teams can search mail logs for specific subject strings to identify affected users, the subject line lacks a fixed technical format and does not function like a hash, IP, or registry path in automated detection. It belongs to the phishing delivery phase, not to the post-compromise artifacts that IoC analysis typically targets.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.