Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A Windows system is suspected of having malware that maintains persistence by starting every time a user logs in. Which registry key should be examined FIRST for this persistence mechanism?

⚠ Common exam trap

In CHFI, the trap is that candidates might confuse persistence mechanisms like ShellBags (view settings) or SAM (credentials) with startup entries, leading them to pick a wrong answer. The Run keys (HKCU and HKLM) are the standard locations for user logon persistence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run keys

The Run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) are the most common and straightforward persistence mechanism for malware that executes on user login. These registry keys specify programs that automatically run when a user logs into their account, making them the first place to check for such persistence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ShellBags

    Why it's wrong here

    ShellBags are registry keys located under HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags and BagMRU that persist per-folder Explorer window settings (window size, position, icon layout, and column widths). They are loaded by explorer.exe purely for UI restoration, never interpreted as executable autostart entries. While extremely useful for digital forensics to prove a user browsed specific folders, they cannot execute malware at logon, so they are not a persistence mechanism.

  • ✗

    NTUSER.DAT

    Why it's wrong here

    NTUSER.DAT is the on-disk backing file for the HKCU registry hive, containing a user's configuration, including environment variables, printer mappings, and desktop preferences. While logon persistence entries like HKCU\Software\Microsoft\Windows\CurrentVersion\Run live inside this hive, the hive itself is a passive data container rather than an executable location. Selecting NTUSER.DAT as the answer confuses the storage medium with the specific active key; the actual autostart trigger is the Run subkey, not the hive file.

  • ✓

    Run keys

    Why this is correct

    The Run registry keys, specifically HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, define programs that Windows automatically executes each time a user logs on. Each value name is arbitrary, but the value data is a command line (e.g., C:\Windows\Temp\payload.exe). Malware frequently uses these keys for persistence because they are easy to write, require no elevated privilege for HKCU, and survive a reboot; they are also a primary focus of Autoruns/Windows Defender detections.

  • ✗

    HKLM\SAM

    Why it's wrong here

    HKLM\SAM (Security Account Manager) is a registry hive containing the SAM database with local user account SIDs, and NT/LM password hashes. It is protected with a restrictive ACL so that even administrators cannot read it while the system is running; only SYSTEM has access. Password hashes are used for authentication, not for program launch. There is no value in HKLM\SAM that specifies autostart commands, so it is categorically unrelated to logon persistence.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.