Courseiva

System Monitoring Tools for Dynamic Malware Analysis

During a malware analysis, an analyst uses a tool to monitor registry changes, file system modifications, and process activity simultaneously. Which tool is BEST suited for this integrated monitoring?

⚠ Common exam trap

EC-Council often tests the distinction between tools that perform real-time integrated monitoring (Process Monitor) versus tools that offer only snapshot comparisons (Regshot) or specialize in a single subsystem (Process Explorer), leading candidates to confuse Regshot's registry snapshot capability with live monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Process Monitor

Process Monitor (ProcMon) is the correct tool because it integrates real-time monitoring of registry changes, file system modifications, and process/thread activity into a single interface. It combines the legacy tools Regmon (registry) and Filemon (file system) with process monitoring, allowing an analyst to correlate events across all three subsystems simultaneously, which is essential for dynamic malware analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer that captures frames from the NIC via libpcap/WinPcap and decodes protocols such as HTTP, DNS, TLS, and TCP/UDP. It sees only data crossing the network interface, with no visibility into the Windows Object Manager, registry APIs, or file-system I/O paths. While it is valuable for spotting C2 traffic or exfiltration payloads, it cannot log process/registry/file-system events and therefore is not the tool in question.

  • ✓

    Process Monitor

    Why this is correct

    Process Monitor is the correct choice because it uses kernel-mode registry callbacks, a file-system minifilter, and ETW process/thread/network providers to record real-time operations with full paths, operation types, results, durations, and call stacks. It lets an analyst filter by process name, PID, registry key, file path, or operation, and preserve the event timeline in a PML log for detailed malware-behavior reconstruction. This makes it a true dynamic behavioral monitor rather than a packet capture or state-snapshot utility.

  • ✗

    Regshot

    Why it's wrong here

    Regshot captures a registry hive snapshot (and optionally hashes of selected directories) before and after an execution, then performs an offline diff to report keys and values that were added, deleted, or changed. It is a one-shot comparison tool, not a real-time logger, so it cannot reveal transient artifacts that appear and are deleted during the run, nor attribute operations to the responsible process. Its lack of file-system and process event monitoring makes it unsuitable for the continuous monitoring scenario described.

  • ✗

    Process Explorer

    Why it's wrong here

    Process Explorer shows a live process tree with per-process handles for files, registry keys, and network endpoints, along with threads, loaded DLLs, and CPU/memory usage. It is useful for spotting odd parent-child relationships or inspecting an open handle at a single moment, but it does not record an ordered log of registry or file-system changes over time. As a point-in-time introspection utility, it cannot detect operations that occur and roll back during execution, so it is not the monitoring tool being described.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.