CHFI Mobile and Malware Forensics Practice Question
During a malware investigation, you find that a process named `svchost.exe` is making outbound connections to an IP address known to be malicious. What tool would be BEST to capture the network traffic for further analysis?
⚠ Common exam trap
EC-Council often tests the distinction between process analysis tools (like Process Explorer) and network analysis tools (like Wireshark), leading candidates to mistakenly choose Process Explorer because it can show network connections in its lower pane, but it cannot capture or inspect packet contents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wireshark
Wireshark is the best tool for capturing and analyzing network traffic because it can intercept packets at the network interface level, allowing you to inspect the full payload and headers of outbound connections from `svchost.exe` to the malicious IP. This enables deep analysis of protocols, data exfiltration attempts, and command-and-control communication patterns, which is essential in malware forensics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PEiD
Why it's wrong here
PEiD is a static analysis tool that identifies packers, cryptors, and compiler signatures in portable executable headers. It scans file structure and entropy to detect obfuscation, but it does not capture or interpret network packets. Consequently, it cannot show what data a process sends over the wire, making it unsuitable for network traffic analysis.
- ✗
Process Explorer
Why it's wrong here
Process Explorer is a Sysinternals utility that displays running processes in a hierarchical tree along with their opened handles, loaded DLLs, and basic performance data. While it can enumerate per-process TCP/UDP endpoints, it does not capture the actual packet payloads or reconstruct protocol conversations. Therefore it provides only connection metadata, not the traffic content needed for deep packet inspection.
- ✗
Regshot
Why it's wrong here
Regshot captures two snapshots of the Windows registry at different times and compares them to report added, deleted, or modified keys and values. This is invaluable for spotting persistence mechanisms, but it has no network monitoring capability. A malware process may alter registry keys and also exfiltrate data; Regshot can only document the former, not capture the network communication.
- ✓
Wireshark
Why this is correct
Wireshark is the correct tool because it is a network protocol analyzer that captures live packets and decodes hundreds of protocols, allowing you to inspect individual frames, follow TCP streams, and filter traffic by IP, port, or protocol. In a malware investigation, it reveals command-and-control activity, malicious payloads, and data exfiltration patterns associated with the suspicious process's network communications.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.