CHFI Mobile and Malware Forensics Practice Question
An analyst is performing dynamic analysis of a malware sample in Cuckoo Sandbox. Which TWO of the following are typical indicators of command and control (C2) communication?
⚠ Common exam trap
EC-Council often tests the distinction between local host artifacts (persistence, mutexes, file modifications) and network-based C2 indicators, tricking candidates into selecting any suspicious behavior rather than focusing specifically on outbound communication patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The malware performs DNS queries to a domain that resolves to a known malicious IP
Option B is correct because DNS queries to a domain resolving to a known malicious IP are a classic C2 indicator: the malware must locate its controller, and threat-intel feeds flag such resolutions as beaconing to adversary infrastructure. Option E is correct because HTTP POST requests to a newly registered domain (2 days old) fit the C2 profile of exfiltrating victim data or receiving tasking over web protocols, and domain age is a strong reputation signal for malicious infrastructure. Option A is not a C2 indicator but a persistence technique via the Registry Run key. Option C describes system file modification, which indicates tampering or defense evasion rather than network C2. Option D describes mutex creation, which is typically used for single-instance checks or host-based sandbox-evasion markers, not command-and-control traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The malware creates a registry run key for persistence
Why it's wrong here
A registry run key persistence indicator means the malware is configured to launch automatically after a reboot, typically via HKCU\Software\Microsoft\Windows\CurrentVersion\Run. While this shows survivability and is a common malware trait, it does not reveal any network communication with an attacker. C2 requires an external channel to issue commands or receive stolen data; a Run key only ensures the malware remains loaded on the next logon, so it is not a C2 indicator.
- ✓
The malware performs DNS queries to a domain that resolves to a known malicious IP
Why this is correct
DNS queries to a domain that resolves to a known malicious IP are a classic C2 beaconing signature because the malware must resolve the hostname of its command-and-control server before establishing a session. During dynamic analysis, repeated DNS lookups to a domain tied to a malicious address indicate that the sample is attempting to reach infrastructure controlled by the attacker. The reputation correlation of the resolved IP raises the confidence that this is C2 communication rather than unrelated background traffic.
- ✗
The malware modifies system files in C:\Windows\System32
Why it's wrong here
Modifying files in C:\Windows\System32 may be used to implant a backdoor, replace a DLL for hijacking, or disable system protections, but it does not inherently involve command-and-control traffic. Such changes are more closely tied to persistence, privilege escalation, or defense evasion, as they alter the execution path of trusted binaries. Unless the modified file is specifically observed generating network connections to an attacker, this behavior alone does not demonstrate C2 communication.
- ✗
The malware creates a mutex named 'Global\MyMutex'
Why it's wrong here
Creating a mutex named 'Global\MyMutex' is a synchronization primitive that prevents multiple instances of the malware from running simultaneously, which would otherwise cause instability or duplicate operations. This is often one of the first actions malware takes to ensure single-instance execution, and it tells the analyst which instance is active, but it has no network component. A mutex is therefore a relevant stability or anti-detection behavior, not an indicator of command-and-control activity.
- ✓
The malware makes HTTP POST requests to a domain registered 2 days ago
Why this is correct
HTTP POST requests to a domain registered only two days ago are a strong C2 indicator because attackers typically register fresh domains to avoid reputation-based blocklists; the POST method is used to upload stolen data or receive encrypted commands from the server. Combined with the very recent domain registration, this network behavior shows intentional communication with attacker-controlled infrastructure that is unlikely to be a legitimate service. Dynamic analysis should correlate the HTTP session content and destination IP to confirm the command-and-control channel.
Visual reference
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.