Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

An incident responder finds a suspicious LNK file in a user's Startup folder on a Windows system. The LNK file's target is "C:\Windows\System32\rundll32.exe" with a command-line argument "javascript:" followed by encoded text. What is the most likely purpose of this shortcut?

⚠ Common exam trap

Test-takers frequently assume rundll32.exe is only for DLL execution and overlook its ability to run script protocols, leading them to dismiss the malicious intent and choose a benign option like a legitimate update or automation script.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A malicious persistence mechanism to execute payload via script

The LNK file targets rundll32.exe with a JavaScript command-line argument, which is a known technique for executing arbitrary script code without writing a traditional executable to disk. This is commonly used by malware to establish persistence by placing the shortcut in the Startup folder, ensuring the script runs each time the user logs in.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A shortcut to a network resource that failed

    Why it's wrong here

    A failed network resource shortcut targets a UNC path such as \\server\share and attempts an SMB connection; it would produce a 'network path not found' error at most. The suspicious LNK contains rundll32.exe with inline JavaScript in its command line, which is not a filesystem reference. This is a code-execution invocation, not a pointer to a network location, so it cannot be dismissed as a dead shortcut.

  • ✗

    Legitimate update mechanism for Microsoft Office

    Why it's wrong here

    Microsoft Office updates use trusted, signed executables such as setup.exe or msiexec, usually via Windows Update, and never interpret JavaScript directly through rundll32.exe. A .lnk file that triggers rundll32.exe with a javascript: payload is not part of any legitimate Office update mechanism. The JavaScript payload would run arbitrary code, not update software, and the shortcut's placement in a user directory suggests persistence rather than an installer.

  • ✗

    A user-created automation script for daily tasks

    Why it's wrong here

    User-created automation scripts are typically .bat, .ps1, .vbs, or scheduled tasks, not a lone .lnk file invoking rundll32.exe with JavaScript. Even a benign shortcut would not need to hide command-line arguments or use a system binary to interpret script code. This behavior is a known evasion technique, and the shortcut likely was placed to maintain persistence, not to automate routine tasks.

  • ✓

    A malicious persistence mechanism to execute payload via script

    Why this is correct

    This is a classic Living-off-the-Land (LOLBin) technique: rundll32.exe, a signed Windows binary, can be abused to execute JavaScript via its exported functions, allowing malware to run under a legitimate process name. The .lnk file acts as a persistence mechanism, typically placed in the Startup folder or run key, and launches the JavaScript payload at logon to download and execute additional malware. This matches MITRE ATT&CK T1218.011, using a trusted binary to evade detection and achieve persistence.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.