Courseiva
OS and Network Forensics →hardMultiple Select

Windows Persistence Mechanisms in Forensics

Which THREE of the following are commonly used for persistence on a Windows system? (Choose THREE.)

Quick Answer

The answer is Registry Run keys, scheduled tasks, and service installations. These three mechanisms are commonly used for persistence on a Windows system because they allow malware or unauthorized code to automatically execute each time the system boots or a user logs in, leveraging core Windows components that are designed for legitimate administrative or software functionality. On the Computer Hacking Forensic Investigator CHFI exam, this question tests your ability to distinguish between active persistence methods and passive forensic artifacts; a common trap is confusing Prefetch files or LNK files—which are valuable for timeline analysis and evidence of execution—with actual persistence mechanisms. Remember that persistence requires an automatic trigger for re-execution, not just a record of past activity. A useful memory tip is to think of the three S’s: Startup keys (Registry Run), Scheduler (tasks), and Services—each ensures code runs again without user intervention.

⚠ Common exam trap

EC-CHFI often tests the distinction between execution artifacts (like Prefetch files) and actual persistence mechanisms, leading candidates to mistakenly select Prefetch because it records execution, but it does not cause automatic re-execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Registry Run keys

Registry Run keys (B) are a classic Windows persistence mechanism because entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run are automatically executed at user logon or system startup. Service installations (C) provide persistence by registering a service with the Service Control Manager (e.g., via sc.exe create or New-Service), allowing malicious code to run at boot under a privileged context. Scheduled tasks (E) persist by creating a task through schtasks.exe or the Task Scheduler COM API that triggers execution at logon, startup, or on a schedule. LNK files (A) are shortcut files that can execute payloads when clicked but are not an automatic persistence mechanism by themselves, and Prefetch files (D) are forensic artifacts generated by the Windows prefetcher to speed up application launches, not a persistence technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LNK files

    Why it's wrong here

    LNK files are shortcut artefacts recording recent user activity, useful for evidence of execution or accessed files, but Windows does not execute them at logon to relaunch malware. They are tempting because they persist on disk and reveal user behaviour, which suits forensic timeline reconstruction rather than persistence.

  • ✓

    Registry Run keys

    Why this is correct

    Run keys under HKCU and HKLM execute specified programs at user logon or system start, giving malware automatic re-execution across reboots. This satisfies the persistence requirement by surviving restarts without further user action, unlike one-off execution or volatile artefacts.

  • ✓

    Service installations

    Why this is correct

    Malware installs a Windows service so its executable launches automatically at boot under the Service Control Manager. This satisfies the stem's requirement for a persistence mechanism, since the service survives reboots and restarts without further user interaction.

  • ✗

    Prefetch files

    Why it's wrong here

    Prefetch files cache application loading data to speed subsequent launches; Windows does not use them to restart programs at boot or logon, so they cannot maintain persistence. They are tempting because they survive reboots and evidence execution, making them valuable for forensic analysis of what ran and when.

  • ✓

    Scheduled tasks

    Why this is correct

    Scheduled tasks let malware register a trigger that launches its payload at logon, boot or on a recurring schedule via the Task Scheduler. This satisfies the stem's requirement for a persistence mechanism, surviving reboots and often masquerading as legitimate maintenance jobs.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are common persistence mechanisms used by malware on Windows systems? (Select two.)

easy
  • A.USBSTOR registry key
  • B.Prefetch files
  • ✓ C.Scheduled Tasks
  • D.LNK files
  • ✓ E.Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run)

Why C: Scheduled Tasks (C) are a common persistence mechanism because malware can register a task via schtasks.exe or the Task Scheduler COM API to execute a payload at logon, on a schedule, or on system events, surviving reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that Windows processes at user logon, so malware placed there launches automatically each session. The other options are forensic artifacts rather than persistence methods: USBSTOR records historical USB mass-storage connections, Prefetch files evidence program execution for performance, and LNK files are shortcut artifacts often used for initial execution or user bait, not for maintaining persistence.

Variation 2. Which TWO of the following are persistence mechanisms commonly found in Windows forensics? (Select two.)

easy
  • A.Jump lists
  • B.ShellBags
  • ✓ C.Scheduled Tasks
  • D.Prefetch files
  • ✓ E.Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run)

Why C: Scheduled Tasks (C) are a well-known Windows persistence mechanism because an attacker can register a task via schtasks.exe or the Task Scheduler that launches malware at logon, on a schedule, or on system events, and these tasks survive reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that execute listed programs at user logon, making them a common persistence technique. By contrast, Jump lists (A) are artifacts recording recently accessed files and applications for forensic reconstruction, not autostart mechanisms. ShellBags (B) store folder view settings and window preferences in the registry to show user navigation history, and Prefetch files (D) are performance artifacts in C:\Windows\Prefetch that record executed program traces, neither of which causes programs to run automatically at startup.

Variation 3. Which TWO of the following registry keys are commonly used to maintain persistence on Windows systems by automatically starting programs?

hard
  • A.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
  • B.HKLM\SAM\SAM\Domains\Account\Users
  • C.HKLM\System\CurrentControlSet\Services
  • ✓ D.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
  • ✓ E.HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

Why D: Option D, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, is correct because the Run key under the current user's hive causes Windows to automatically launch the listed programs at each logon, making it a classic per-user persistence location. Option E, HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce, is correct because the RunOnce key under the machine hive automatically executes its entries once at the next logon or startup and then removes them, which is commonly abused for persistence. Option A, HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, merely stores paths to user shell folders such as Desktop and Startup and does not itself launch programs. Option B, HKLM\SAM\SAM\Domains\Account\Users, holds local account and credential-related data, not autostart entries. Option C, HKLM\System\CurrentControlSet\Services, defines service configuration and can be abused for persistence, but it is not one of the two commonly cited Run/RunOnce autostart keys asked for here.

Variation 4. Which of the following Windows registry keys is commonly used by malware to achieve persistence by executing a program at user logon?

medium
  • A.HKEY_LOCAL_MACHINE\SAM\SAM
  • B.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
  • ✓ C.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
  • D.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

Why C: The HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run registry key is specifically designed to launch programs automatically when the current user logs on. Malware commonly writes a value pointing to its executable under this key to achieve user-level persistence without requiring administrative privileges, as it runs in the context of the logged-on user.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.