Courseiva

CHFI Mobile and Malware Forensics Practice Question

Which THREE of the following are common indicators of compromise (IoCs) that can be used to detect malware infections?

⚠ Common exam trap

EC-Council often tests the distinction between user-specific or hardware-specific attributes (like favorite color or computer brand) and actual system-level artifacts that indicate compromise, leading candidates to mistakenly include irrelevant options if they do not focus on technical IoCs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Registry key created by malware for persistence

Option C is correct because malware frequently establishes persistence by creating or modifying registry keys (for example, under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or as a service entry), and such unauthorized registry changes are a classic host-based IoC. Option D is correct because cryptographic file hashes such as MD5 or SHA-256 uniquely identify known malicious files, allowing defenders to scan endpoints and compare against threat-intelligence hash feeds. Option E is correct because the IP address of a command-and-control (C2) server is a network-based IoC that can be blocked at the firewall or detected in proxy, DNS, and NetFlow logs to reveal infected hosts beaconing out. Options A and B are not IoCs: a user's favorite color and the brand of a victim's computer are irrelevant personal or hardware attributes that provide no technical evidence of malware activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user's favorite color

    Why it's wrong here

    A user's favorite color is a subjective personal preference that cannot be extracted from system logs, memory images, or network traffic. Indicators of compromise must be observable technical artifacts tied to attacker behavior, whereas color preference leaves no forensic footprint and has no correlation with breach activity. Consequently, it cannot help detect, contain, or investigate an intrusion.

  • ✗

    The brand of the victim's computer

    Why it's wrong here

    The brand of the victim's computer, such as Dell, HP, or Lenovo, is a static hardware attribute that is visible before and after an attack and is not altered by malicious activity. Unless a campaign specifically exploits a model-specific vulnerability or firmware backdoor, the manufacturer alone supplies no evidence of unauthorized access. Treating brand as an indicator of compromise is a logical error because it does not differentiate a compromised system from an identical, uninfected one.

  • ✓

    Registry key created by malware for persistence

    Why this is correct

    Malware often writes or modifies registry keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run to achieve persistence across reboots. This registry modification is a concrete host-based indicator of compromise, because it represents an unauthorized change to the system by the attacker. Security analysts can correlate the key path and subkeys with known malware names or command-line parameters to confirm an infection and determine where to mount a defense.

  • ✓

    MD5 or SHA-256 hash of the malware file

    Why this is correct

    An MD5 or SHA-256 hash is a cryptographic fingerprint derived from the exact bytes of the malware executable, making it a highly specific file-based indicator for identifying known samples. Once a malicious binary is hashed and recorded in threat intelligence, products can flag identical copies on disk or in transit. This hash is valuable for quickly detecting the same artifact across multiple systems, though it changes if a file is modified or re-packed.

  • ✓

    IP address of the command and control server

    Why this is correct

    The IP address of a command and control server is a network-based indicator showing where the compromised host sends beacons or receives instructions. This address can be extracted from proxy, DNS, or flow records, and matching outbound traffic to a known malicious IP strongly suggests active control of the victim. However, analysts must consider that the IP may be a legitimate service abused as C2, so it is often used in combination with domain names and TLS certificate metadata.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.