Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A Windows system has been compromised. The analyst finds a registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run with value name 'UpdateService' pointing to C:\Users\Public\svchost.exe. Why is this particularly suspicious?

⚠ Common exam trap

In CHFI exams, a common trap is the misconception that any svchost.exe outside System32 is automatically malicious, but the real forensic indicator is the path anomaly. Candidates may overlook this and focus on the generic name or the fact that Run keys are for programs, not services, missing the core indicator of process masquerading.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The path is not typical for svchost.exe, which resides in System32

The legitimate svchost.exe is a critical Windows system binary located in C:\Windows\System32. An executable named svchost.exe running from C:\Users\Public\ is a classic masquerading technique used by malware to evade detection by mimicking a trusted process name while residing in a user-writable, non-standard directory. This path deviation is the primary red flag because system processes should never execute from user profile or public folders.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The path is not typical for svchost.exe, which resides in System32

    Why this is correct

    Svchost.exe is a critical Windows service host process that must reside in C:\Windows\System32 (or SysWOW64 on 64-bit systems for 32-bit services). A legitimate svchost.exe never runs from a user profile directory, such as C:\Users\<username>\AppData\Roaming, because that would violate Windows binary protection and signature requirements. The unexpected path alone is a strong indicator of malware, as attackers often name rogue executables svchost.exe to blend in with legitimate processes while locating them in writable, non-standard folders.

  • ✗

    Run keys are only for startup programs, not services

    Why it's wrong here

    This statement mischaracterizes the purpose of Run registry keys. While Run keys are commonly used to launch applications at logon, they are not restricted to startup programs—they can be used to start any executable, including a malicious one that mimics a service. In this scenario, the presence of a Run key that launches an exe is entirely consistent with persistence via the registry; the real anomaly is the executable's location, not the key's type.

  • ✗

    The run key is disabled in Windows 10

    Why it's wrong here

    Run keys, specifically HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, remain fully functional in Windows 10 and Windows 11. They are a widely abused persistence mechanism and are not disabled by default, nor does Windows 10 deprecate them. Therefore, a run key entry is not inherently benign or inert, and an executable launched from such a key must be scrutinized.

  • ✗

    The registry value name 'UpdateService' is too generic

    Why it's wrong here

    While malware authors often use generic or service-like names such as 'UpdateService' to evade suspicion, the choice of value name is not a technical flaw. Registry value names are arbitrary strings and do not affect execution; the operating system simply reads the command line associated with the value. The stronger forensic indicator is the executable's path, which deviates from the legitimate svchost.exe location, making the path-based evidence more probative than the value name.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.