CHFI Mobile and Malware Forensics Practice Question
Which THREE of the following are common indicators of compromise (IoCs) that can be used to detect malware infections?
⚠ Common exam trap
EC-Council often tests the distinction between user-specific or hardware-specific attributes (like favorite color or computer brand) and actual system-level artifacts that indicate compromise, leading candidates to mistakenly include irrelevant options if they do not focus on technical IoCs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Registry key created by malware for persistence
Option C is correct because malware frequently establishes persistence by creating or modifying registry keys (for example, under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or as a service entry), and such unauthorized registry changes are a classic host-based IoC. Option D is correct because cryptographic file hashes such as MD5 or SHA-256 uniquely identify known malicious files, allowing defenders to scan endpoints and compare against threat-intelligence hash feeds. Option E is correct because the IP address of a command-and-control (C2) server is a network-based IoC that can be blocked at the firewall or detected in proxy, DNS, and NetFlow logs to reveal infected hosts beaconing out. Options A and B are not IoCs: a user's favorite color and the brand of a victim's computer are irrelevant personal or hardware attributes that provide no technical evidence of malware activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's favorite color
Why it's wrong here
A user's favorite color is a subjective personal preference that cannot be extracted from system logs, memory images, or network traffic. Indicators of compromise must be observable technical artifacts tied to attacker behavior, whereas color preference leaves no forensic footprint and has no correlation with breach activity. Consequently, it cannot help detect, contain, or investigate an intrusion.
- ✗
The brand of the victim's computer
Why it's wrong here
The brand of the victim's computer, such as Dell, HP, or Lenovo, is a static hardware attribute that is visible before and after an attack and is not altered by malicious activity. Unless a campaign specifically exploits a model-specific vulnerability or firmware backdoor, the manufacturer alone supplies no evidence of unauthorized access. Treating brand as an indicator of compromise is a logical error because it does not differentiate a compromised system from an identical, uninfected one.
- ✓
Registry key created by malware for persistence
Why this is correct
Malware often writes or modifies registry keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run to achieve persistence across reboots. This registry modification is a concrete host-based indicator of compromise, because it represents an unauthorized change to the system by the attacker. Security analysts can correlate the key path and subkeys with known malware names or command-line parameters to confirm an infection and determine where to mount a defense.
- ✓
MD5 or SHA-256 hash of the malware file
Why this is correct
An MD5 or SHA-256 hash is a cryptographic fingerprint derived from the exact bytes of the malware executable, making it a highly specific file-based indicator for identifying known samples. Once a malicious binary is hashed and recorded in threat intelligence, products can flag identical copies on disk or in transit. This hash is valuable for quickly detecting the same artifact across multiple systems, though it changes if a file is modified or re-packed.
- ✓
IP address of the command and control server
Why this is correct
The IP address of a command and control server is a network-based indicator showing where the compromised host sends beacons or receives instructions. This address can be extracted from proxy, DNS, or flow records, and matching outbound traffic to a known malicious IP strongly suggests active control of the victim. However, analysts must consider that the IP may be a legitimate service abused as C2, so it is often used in combination with domain names and TLS certificate metadata.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.