Which TWO of the following are common persistence mechanisms used by malware on Windows systems? (Select two.)
Scheduled Tasks let malware register a trigger that launches its payload at logon, boot or on a timer, surviving reboots and often masquerading as legitimate maintenance. This satisfies the persistence requirement by re-establishing execution without user interaction.
Why this answer
Scheduled Tasks (C) are a common persistence mechanism because malware can register a task via schtasks.exe or the Task Scheduler COM API to execute a payload at logon, on a schedule, or on system events, surviving reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that Windows processes at user logon, so malware placed there launches automatically each session. The other options are forensic artifacts rather than persistence methods: USBSTOR records historical USB mass-storage connections, Prefetch files evidence program execution for performance, and LNK files are shortcut artifacts often used for initial execution or user bait, not for maintaining persistence.
Exam trap
EC-Council often tests the distinction between artifacts of execution (like Prefetch and LNK files) and actual persistence mechanisms that cause automatic re-execution, leading candidates to mistakenly select options that indicate malware ran but do not ensure it runs again.