Courseiva

CHFI Mobile and Malware Forensics Practice Question

An incident responder is analyzing a compromised Windows workstation. Which TWO artifacts would provide the STRONGEST evidence of a malware persistence mechanism?

⚠ Common exam trap

The CHFI exam often tests the distinction between infection vector artifacts (like browser history) and persistence mechanism artifacts (like Run keys or scheduled tasks), trapping candidates who confuse how malware arrives with how it survives a reboot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Registry Run key referencing a suspicious path

Option B is correct because the Windows Registry Run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run) are a classic autostart location that causes a program to execute automatically at user logon or system boot, so a Run key referencing a suspicious path is direct evidence of a persistence mechanism. Option C is correct because a Scheduled Task (stored under C:\Windows\System32\Tasks and managed via schtasks.exe or the Task Scheduler service) configured to launch a malicious executable is an explicit, recurring persistence technique that survives reboots and often runs with elevated privileges. Option A is not the strongest evidence because a user login event (e.g., Event ID 4624 in the Security log) only shows authentication activity and does not itself establish persistence. Option D is not the strongest evidence because network share access logs record file access over SMB and do not demonstrate an autostart or persistence configuration. Option E is not the strongest evidence because browser history showing a suspicious download indicates possible initial infection or delivery, not an established persistence mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event log entry for user login

    Why it's wrong here

    A Windows event log entry for user login (e.g., Event ID 4624) indicates an authentication session, which is a routine occurrence in normal system operation. Even if the login time or account is anomalous, the event itself does not configure any future execution or automatic startup. Persistence forensics focuses on mechanisms that survive reboots, such as services, scheduled tasks, or Registry modifications. Therefore, a login event is a symptom of activity, not evidence of a persistence mechanism.

  • ✓

    Registry Run key referencing a suspicious path

    Why this is correct

    The Registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is a standard autorun location that launches specified executables at user logon. A suspicious path, particularly one outside standard program directories or with randomized naming, is a strong indicator of malware persistence. By writing a value here, the attacker ensures the payload executes automatically on every logon, making it a definitive persistence artifact. This is exactly the kind of evidence an incident responder would flag as critical.

  • ✓

    Scheduled Task entry pointing to a malicious executable

    Why this is correct

    A Scheduled Task entry pointing to a malicious executable is a common persistence method because tasks can trigger execution at logon, system startup, or specified intervals. Attackers often create tasks that run with SYSTEM privileges or under a service account to achieve elevated execution. The presence of such an entry demonstrates a persistent execution trigger, as the Task Scheduler service will automatically invoke the configured command. This qualifies as clear, actionable evidence of persistence.

  • ✗

    Network share access logs

    Why it's wrong here

    Network share access logs record SMB connections to shared folders, typically capturing source IPs, authenticated usernames, and connection times. While useful for identifying lateral movement or data exfiltration, they do not demonstrate an autorun mechanism that executes code automatically after a reboot. A share access is a transient, user- or service-initiated event, not a persistent configuration change. Without a separate autorun entry, this log alone cannot establish persistence.

  • ✗

    Browser history showing download of a suspicious file

    Why it's wrong here

    Browser history showing a suspicious download indicates the initial infection vector, i.e., how the malware entered the system. A downloaded file is inert until executed; without an accompanying autorun entry, service, or scheduled task, it does not cause code to run automatically after reboot. Persistence requires a mechanism that maintains the malware's presence across power cycles. Thus, browser history provides evidence of delivery, not persistence, and would be categorized under initial access rather than persistence.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.