CHFI Mobile and Malware Forensics Practice Question
An analyst is performing malware analysis and executes a suspicious binary in a sandbox. The sandbox reports that the binary creates a mutex named 'Global\DRIVER_UPDATE_MTX' before attempting to connect to 'http://malicious.com/update'. Which tool would BEST capture the network traffic during dynamic analysis?
⚠ Common exam trap
EC-Council often tests the distinction between host-based monitoring tools (like Process Monitor and Process Explorer) and network-based capture tools (like Wireshark), leading candidates to choose a host-based tool when the question explicitly asks for network traffic capture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wireshark
Wireshark is the correct tool because it captures and analyzes network packets at the protocol level, allowing the analyst to inspect the HTTP request to 'http://malicious.com/update', including headers, payload, and any subsequent data exfiltration. Dynamic analysis of malware requires monitoring network traffic to identify command-and-control (C2) communications, and Wireshark provides full packet capture (PCAP) for this purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Regshot
Why it's wrong here
Regshot is a registry and file system snapshot comparison utility, not a network monitoring tool. It takes a baseline snapshot of the registry and file system before executing a sample, then a second snapshot after execution, and diffs them to identify persistent modifications. Because it never touches the network stack or inspects packets, it cannot detect command-and-control beacons, DNS queries, or any other network indicators.
- ✓
Wireshark
Why this is correct
Wireshark is a full-featured network protocol analyzer that captures raw frames on a network interface and decodes hundreds of protocols, from Ethernet through application layers. For malware analysis, it is the standard tool for observing live command-and-control (C2) sessions, exfiltration attempts, or scanning activity. Analysts can filter for suspicious IPs, follow TCP streams to reconstruct payloads, and read pre-recorded packet capture (PCAP) files, making it ideal for this scenario.
- ✗
Process Explorer
Why it's wrong here
Process Explorer is a Sysinternals process management and diagnostics tool that provides a hierarchical view of running processes, with detailed metadata such as loaded DLLs, handles, and security tokens. Although its TCP/IP tab can display existing network connections and remote addresses per process, it does not capture or decode the actual network packets or their payloads. Therefore it cannot analyze real-time C2 traffic content or reconstruct the malware's network communications.
- ✗
Process Monitor
Why it's wrong here
Process Monitor is a Sysinternals monitoring tool that uses kernel drivers to capture real-time file system, registry, and process/thread activity, along with some named pipe and TCP/UDP connection events. It is designed to trace program interactions with the operating system, not to sniff or dissect raw network packet data. Thus it cannot reveal the content of network communications, such as encrypted C2 command streams, and is not suitable for packet-level traffic analysis.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.