CHFI Mobile and Malware Forensics Practice Question
Which of the following is an example of an indicator of compromise (IoC) that can be used to detect malware on a network?
⚠ Common exam trap
EC-Council often tests the distinction between network-based and host-based IoCs, and the trap here is that candidates mistakenly classify host-level artifacts (mutex, registry, hash) as network IoCs because they are common in malware analysis, but the question explicitly asks for an indicator 'on a network'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A known malicious IP address
A known malicious IP address is a classic indicator of compromise (IoC) because it directly identifies a command-and-control (C2) server or a source of malicious traffic. Network monitoring tools can match outbound or inbound connections against threat intelligence feeds of known bad IPs, triggering an alert. This is a network-based IoC that requires no host-level analysis, making it ideal for initial detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A mutex name
Why it's wrong here
A mutex (mutual exclusion) object is an operating system synchronization primitive, and malware often creates a uniquely named mutex to ensure only one instance runs at a time. Its name is discovered by inspecting process objects, memory dumps, or kernel handles on the compromised host, making it a host-based indicator of compromise rather than a network-based one. Therefore, a mutex name would not be the correct answer when selecting a network-level IoC.
- ✓
A known malicious IP address
Why this is correct
A known malicious IP address is a network-based indicator of compromise because it is observed in network telemetry, such as connections to a command-and-control (C2) server, phishing infrastructure, or malware distribution points. Analysts identify it through flow logs, DNS queries, or proxy logs, and it reflects external communication from the victim environment. Because it is a network artifact rather than an endpoint artifact, it is the correct answer for a network-level IoC.
- ✗
A registry key modification
Why it's wrong here
A registry key modification changes persistent Windows configuration, and malware commonly alters keys to maintain persistence after reboot or to disable security mechanisms. These modifications are detected on the local endpoint via file/registry monitoring tools or event IDs, not by inspecting network traffic. Therefore, a registry change is a host-based indicator and would be incorrect if the question asks for a network-derived IoC.
- ✗
A file's MD5 hash
Why it's wrong here
An MD5 hash is a cryptographic digest that uniquely identifies a file's binary content, and defenders use it to match known malicious executables during endpoint scans, malware analysis, and forensic triage. Although it can be embedded in network inspection rules to detect file transfers, the hash itself is computed from a host artifact and is fundamentally classified as a host-based IoC. Thus, a file's MD5 hash is not a network-based indicator and would not be the correct selection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.