Courseiva

CHFI Mobile and Malware Forensics Practice Question

During a malware investigation, an analyst identifies a suspicious file that appears to be a Windows executable. Using PEiD, the analyst detects the file is packed with UPX. After unpacking, the analyst runs the file in a sandbox and observes it modifies the following registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MalService. What behavioural indicator is primarily demonstrated?

⚠ Common exam trap

EC-Council often tests the distinction between persistence and privilege escalation, where candidates mistakenly think modifying HKCU\Run requires administrative rights, but it only requires user-level access and is a persistence technique, not an escalation attempt.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Persistence mechanism

The modification of the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MalService is a classic persistence mechanism. By adding an entry to the Run key, the malware ensures that it executes automatically every time the user logs into the system, maintaining its presence across reboots.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Persistence mechanism

    Why this is correct

    Adding a value to the Run or RunOnce registry key is a classic persistence mechanism because those keys are automatically processed at user logon. The shell (explorer.exe) reads entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, executing the specified command without requiring any additional user interaction. This ensures the malware re-launches after a reboot, making it a strong indicator of an autostart persistence technique.

  • ✗

    Command and control communication

    Why it's wrong here

    Command and control (C2) communication requires the malware to establish a network channel to an external server, typically via HTTP/HTTPS, DNS, or raw TCP/UDP, to receive instructions or exfiltrate data. The evidence described—a Run key modification—is a purely local registry artifact and contains no indication of network connections, beaconing intervals, or C2 domains. While persistence mechanisms support long-term control, the Run key itself does not constitute or prove C2 communication without accompanying network telemetry.

  • ✗

    Anti-forensic technique (timestomping)

    Why it's wrong here

    Timestomping is an anti-forensic technique that deliberately alters file system timestamps (such as modification, access, and creation times) using APIs like SetFileTime or tools like timestomp, often targeting artifacts to mislead investigators. The addition of a value to the Run key modifies a registry key's last-write time, not file timestamps, and there is no mention of timestamp anomalies on files or directories. This action is an autostart configuration change, not a timestamp manipulation attack, so classifying it as timestomping would be incorrect.

  • ✗

    Privilege escalation attempt

    Why it's wrong here

    Privilege escalation is the process of gaining higher access rights than currently held, typically from a standard user to an administrator or SYSTEM, via techniques such as token manipulation, service exploitation, or vulnerability exploitation. Adding a Run key entry does not by itself change the privileges of the process that runs at logon; it merely schedules an executable to execute with the same user context and integrity level that the interactive session already has. Since it grants no additional privileges or security token rights, it is a persistence mechanism rather than a privilege escalation attempt.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.