CHFI OS and Network Forensics Practice Question
An incident responder finds a suspicious LNK file in a user's Startup folder on a Windows system. The LNK file's target is "C:\Windows\System32\rundll32.exe" with a command-line argument "javascript:" followed by encoded text. What is the most likely purpose of this shortcut?
⚠ Common exam trap
Test-takers frequently assume rundll32.exe is only for DLL execution and overlook its ability to run script protocols, leading them to dismiss the malicious intent and choose a benign option like a legitimate update or automation script.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A malicious persistence mechanism to execute payload via script
The LNK file targets rundll32.exe with a JavaScript command-line argument, which is a known technique for executing arbitrary script code without writing a traditional executable to disk. This is commonly used by malware to establish persistence by placing the shortcut in the Startup folder, ensuring the script runs each time the user logs in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A shortcut to a network resource that failed
Why it's wrong here
A failed network resource shortcut targets a UNC path such as \\server\share and attempts an SMB connection; it would produce a 'network path not found' error at most. The suspicious LNK contains rundll32.exe with inline JavaScript in its command line, which is not a filesystem reference. This is a code-execution invocation, not a pointer to a network location, so it cannot be dismissed as a dead shortcut.
- ✗
Legitimate update mechanism for Microsoft Office
Why it's wrong here
Microsoft Office updates use trusted, signed executables such as setup.exe or msiexec, usually via Windows Update, and never interpret JavaScript directly through rundll32.exe. A .lnk file that triggers rundll32.exe with a javascript: payload is not part of any legitimate Office update mechanism. The JavaScript payload would run arbitrary code, not update software, and the shortcut's placement in a user directory suggests persistence rather than an installer.
- ✗
A user-created automation script for daily tasks
Why it's wrong here
User-created automation scripts are typically .bat, .ps1, .vbs, or scheduled tasks, not a lone .lnk file invoking rundll32.exe with JavaScript. Even a benign shortcut would not need to hide command-line arguments or use a system binary to interpret script code. This behavior is a known evasion technique, and the shortcut likely was placed to maintain persistence, not to automate routine tasks.
- ✓
A malicious persistence mechanism to execute payload via script
Why this is correct
This is a classic Living-off-the-Land (LOLBin) technique: rundll32.exe, a signed Windows binary, can be abused to execute JavaScript via its exported functions, allowing malware to run under a legitimate process name. The .lnk file acts as a persistence mechanism, typically placed in the Startup folder or run key, and launches the JavaScript payload at logon to download and execute additional malware. This matches MITRE ATT&CK T1218.011, using a trusted binary to evade detection and achieve persistence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.