Courseiva

CHFI Mobile and Malware Forensics Practice Question

During a malware investigation, you find that a process named `svchost.exe` is making outbound connections to an IP address known to be malicious. What tool would be BEST to capture the network traffic for further analysis?

⚠ Common exam trap

EC-Council often tests the distinction between process analysis tools (like Process Explorer) and network analysis tools (like Wireshark), leading candidates to mistakenly choose Process Explorer because it can show network connections in its lower pane, but it cannot capture or inspect packet contents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wireshark

Wireshark is the best tool for capturing and analyzing network traffic because it can intercept packets at the network interface level, allowing you to inspect the full payload and headers of outbound connections from `svchost.exe` to the malicious IP. This enables deep analysis of protocols, data exfiltration attempts, and command-and-control communication patterns, which is essential in malware forensics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PEiD

    Why it's wrong here

    PEiD is a static analysis tool that identifies packers, cryptors, and compiler signatures in portable executable headers. It scans file structure and entropy to detect obfuscation, but it does not capture or interpret network packets. Consequently, it cannot show what data a process sends over the wire, making it unsuitable for network traffic analysis.

  • ✗

    Process Explorer

    Why it's wrong here

    Process Explorer is a Sysinternals utility that displays running processes in a hierarchical tree along with their opened handles, loaded DLLs, and basic performance data. While it can enumerate per-process TCP/UDP endpoints, it does not capture the actual packet payloads or reconstruct protocol conversations. Therefore it provides only connection metadata, not the traffic content needed for deep packet inspection.

  • ✗

    Regshot

    Why it's wrong here

    Regshot captures two snapshots of the Windows registry at different times and compares them to report added, deleted, or modified keys and values. This is invaluable for spotting persistence mechanisms, but it has no network monitoring capability. A malware process may alter registry keys and also exfiltrate data; Regshot can only document the former, not capture the network communication.

  • ✓

    Wireshark

    Why this is correct

    Wireshark is the correct tool because it is a network protocol analyzer that captures live packets and decodes hundreds of protocols, allowing you to inspect individual frames, follow TCP streams, and filter traffic by IP, port, or protocol. In a malware investigation, it reveals command-and-control activity, malicious payloads, and data exfiltration patterns associated with the suspicious process's network communications.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.