Courseiva

CHFI Mobile and Malware Forensics Practice Question

Which of the following is an example of an anti-forensics technique used to hide malicious activity?

⚠ Common exam trap

The CHFI exam often tests the misconception that any technique used by malware (like creating a mutex) is automatically an anti-forensics technique, when in fact anti-forensics specifically targets the forensic process itself (e.g., data hiding, evidence destruction, or timeline manipulation).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Timestomping

Timestomping is an anti-forensics technique that deliberately modifies file timestamps (e.g., MAC times: Modified, Accessed, Created) using tools like `touch` on Linux or `SetFileTime` on Windows. By altering these timestamps, an attacker can hide the true timeline of malicious file creation, modification, or access, thereby evading forensic timeline analysis and making it appear that malicious activity occurred at a different time or was part of legitimate system operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Timestomping

    Why this is correct

    Timestomping is a deliberate anti-forensic technique that alters file system timestamps — specifically the MAC times (modification, access, and change) — using tools like SetMACE or timestomp. By adjusting these metadata values to a false past or future date, an attacker destroys the temporal correlation that investigators rely on to reconstruct a sequence of events. This directly obfuscates the digital trail and impedes timeline analysis, making it a textbook example of anti-forensics.

  • ✗

    Running a sandbox

    Why it's wrong here

    Running a sandbox is not an anti-forensic measure because a sandbox is an analysis environment used to safely execute suspicious code and observe its behavior. In forensic and incident response contexts, sandboxes aid investigation rather than hindering it. While some malware employs anti-sandbox techniques to detect virtualized environments, the act of running a sandbox itself is a defensive analytic technique, not an attempt to covertly destroy or hide evidence.

  • ✗

    Creating a mutex

    Why it's wrong here

    Creating a mutex is a synchronization primitive used by multi-threaded applications to ensure exclusive access to shared resources, and it does not obscure or erase forensic evidence. In fact, malware often creates a mutex with a unique name as a single-instance marker, which analysts can use as an indicator of compromise (IOC). Therefore, a mutex is an operational artifact that may even assist forensic identification, rather than serving an anti-forensic purpose.

  • ✗

    Generating a hash

    Why it's wrong here

    Generating a hash computes a fixed-size digest from data, which is used to verify integrity and authenticate evidence in forensic practice, not to conceal it. Cryptographic hashes like SHA-256 are essential for maintaining a chain of custody by proving that evidence has not been altered. This process is transparent and preserves data fidelity, making it the opposite of an anti-forensic action, which seeks to manipulate or remove data.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.