CHFI Mobile and Malware Forensics Practice Question
Which of the following is an example of an anti-forensics technique used to hide malicious activity?
⚠ Common exam trap
The CHFI exam often tests the misconception that any technique used by malware (like creating a mutex) is automatically an anti-forensics technique, when in fact anti-forensics specifically targets the forensic process itself (e.g., data hiding, evidence destruction, or timeline manipulation).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Timestomping
Timestomping is an anti-forensics technique that deliberately modifies file timestamps (e.g., MAC times: Modified, Accessed, Created) using tools like `touch` on Linux or `SetFileTime` on Windows. By altering these timestamps, an attacker can hide the true timeline of malicious file creation, modification, or access, thereby evading forensic timeline analysis and making it appear that malicious activity occurred at a different time or was part of legitimate system operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Timestomping
Why this is correct
Timestomping is a deliberate anti-forensic technique that alters file system timestamps — specifically the MAC times (modification, access, and change) — using tools like SetMACE or timestomp. By adjusting these metadata values to a false past or future date, an attacker destroys the temporal correlation that investigators rely on to reconstruct a sequence of events. This directly obfuscates the digital trail and impedes timeline analysis, making it a textbook example of anti-forensics.
- ✗
Running a sandbox
Why it's wrong here
Running a sandbox is not an anti-forensic measure because a sandbox is an analysis environment used to safely execute suspicious code and observe its behavior. In forensic and incident response contexts, sandboxes aid investigation rather than hindering it. While some malware employs anti-sandbox techniques to detect virtualized environments, the act of running a sandbox itself is a defensive analytic technique, not an attempt to covertly destroy or hide evidence.
- ✗
Creating a mutex
Why it's wrong here
Creating a mutex is a synchronization primitive used by multi-threaded applications to ensure exclusive access to shared resources, and it does not obscure or erase forensic evidence. In fact, malware often creates a mutex with a unique name as a single-instance marker, which analysts can use as an indicator of compromise (IOC). Therefore, a mutex is an operational artifact that may even assist forensic identification, rather than serving an anti-forensic purpose.
- ✗
Generating a hash
Why it's wrong here
Generating a hash computes a fixed-size digest from data, which is used to verify integrity and authenticate evidence in forensic practice, not to conceal it. Cryptographic hashes like SHA-256 are essential for maintaining a chain of custody by proving that evidence has not been altered. This process is transparent and preserves data fidelity, making it the opposite of an anti-forensic action, which seeks to manipulate or remove data.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.