Courseiva

CHFI Mobile and Malware Forensics Practice Question

In malware forensics, which of the following is an indicator of compromise (IoC) that can be used to detect a specific malware strain across multiple systems?

⚠ Common exam trap

EC-Council often tests the misconception that file metadata like timestamps or sizes are reliable IoCs, when in fact they are easily altered or inconsistent across systems, whereas a cryptographic hash of the binary content provides a deterministic and verifiable identifier.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file's MD5 hash computed from its binary contents

The MD5 hash of a file's binary contents is a unique cryptographic fingerprint that remains consistent across all copies of the exact same malware strain, regardless of where it is stored or what metadata the filesystem assigns. This makes it a reliable indicator of compromise (IoC) for identifying a specific malware sample across multiple systems, as the hash will match even if file names, sizes, or timestamps differ.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file's size in bytes reported by the filesystem

    Why it's wrong here

    File size is an ambiguous property because it is a many-to-one mapping: countless distinct binaries can share the exact same byte length, and malware can be padded or truncated to match any arbitrary size. Moreover, size is derived from filesystem metadata rather than content, so it cannot distinguish a malicious binary from a benign one that happens to occupy the same number of bytes. At best it serves as a coarse filter, never as a definitive indicator of compromise.

  • ✓

    The file's MD5 hash computed from its binary contents

    Why this is correct

    An MD5 hash is computed from the exact binary contents of the file, producing a fixed-length digest that acts as a fingerprint for that specific byte sequence; changing even a single bit results in a completely different digest. In malware forensics, matching a sample's MD5 against a threat intelligence database identifies a known malicious file with high confidence because the digest is directly derived from the bytes, not from mutable metadata. Although MD5 has known collision vulnerabilities, for identifying a particular captured sample it is still a standard and reliable indicator, with SHA-256 preferred for stronger assurance.

  • ✗

    The file's copyright metadata embedded in the PE header

    Why it's wrong here

    Copyright metadata in a PE header, typically stored in the VersionInfo resource, is an unauthenticated, human-readable string that is not verified by the operating system and has no influence on code execution. Because it is trivial for malware authors to modify, strip, or forge this field, it can be deliberately set to impersonate trusted software or left empty to evade detection. Consequently, relying on copyright metadata as an indicator of compromise produces false positives and false negatives.

  • ✗

    The file's creation timestamp as recorded by the operating system

    Why it's wrong here

    The operating system's recorded creation timestamp is stored as filesystem metadata and can be altered by direct manipulation of the filesystem structures, by using antisleuth tools, or simply by copying the file to a new volume, which resets its birth time. Additionally, timestamps are inherently unreliable because malware is often unpacked, recompiled, or extracted in a way that updates the timestamp to the analysis time, and timezone/clock skew can further distort the value. Since it is neither content-derived nor unique, it cannot serve as an indicator of compromise.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.