Courseiva

CHFI Mobile and Malware Forensics Practice Question

Which TWO of the following are anti-forensic techniques used by malware to evade detection?

⚠ Common exam trap

The CHFI exam often tests the distinction between anti-forensic techniques (which actively hide or destroy forensic evidence) and general security mechanisms (like encryption of communication) that do not directly target forensic artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Packing

Packing (A) is an anti-forensic technique because it compresses or encrypts the malware's executable with a runtime unpacker stub, hiding strings, imports, and code from static analysis tools such as disassemblers and signature scanners. Timestomping (C) is anti-forensic because malware deliberately modifies file system timestamps (e.g., $STANDARD_INFORMATION vs. $FILE_NAME attributes in NTFS) to make malicious files appear older or to blend with legitimate files, frustrating timeline analysis. Logging errors (B) is not anti-forensic; it is a normal software development or debugging practice that actually leaves evidence behind. Encryption of communication (D) is a defense-evasion/confidentiality technique for command-and-control traffic, not an anti-forensic technique targeting investigator artifacts. Creating mutexes (E) is a host-based evasion technique to prevent multiple malware instances from running, not a method to defeat forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Packing

    Why this is correct

    Packing is a legitimate software distribution technique that malicious actors repurpose for anti-forensic effect. A packer compresses and often encrypts the original executable payload, embedding it within a decompressor stub, so the on-disk byte sequence no longer matches known malware signatures. At runtime, the stub unpacks the payload in memory, defeating static signature-based scans and complicating file-level triage by forensic investigators.

  • ✗

    Logging errors

    Why it's wrong here

    Logging errors is not an anti-forensic technique; instead, it is a normal operational process that generates log entries, which are typically rich sources of forensic evidence. Anti-forensic techniques are defined by their intent to destroy, hide, or manipulate evidence after the fact, whereas error logging actually creates additional artifacts that investigators can correlate with system events. Therefore, it is the opposite of an anti-forensic action.

  • ✓

    Timestomping

    Why this is correct

    Timestomping is a core anti-forensic technique that deliberately alters file system timestamps, such as MAC (modification, access, change) times, using tools like SetMACE or touch. Forensic investigators rely on timeline analysis to reconstruct the sequence of events leading up to an incident; by falsifying these timestamps, timestomping breaks that temporal chain and misleads reconstruction efforts. Unlike packing, which changes the file's content, timestomping targets metadata to conceal the true timing of malicious activity.

  • ✗

    Encryption of communication

    Why it's wrong here

    Encryption of communication, such as TLS or SSH, protects data in transit from interception but is not specifically an anti-forensic technique because it does not directly manipulate evidence stored on digital media. While it can impede network forensic analysis and obscure exfiltration of stolen data, the classification of anti-forensics focuses on actions that compromise the integrity or availability of artifacts on disk or in memory. Thus, it is an evasion or privacy measure rather than an anti-forensic technique in the strict sense.

  • ✗

    Creating mutexes

    Why it's wrong here

    Creating mutexes is a common programming construct used to prevent multiple instances of a process from running simultaneously; malware often uses them to ensure stable execution, but this leaves a behavioral artifact in memory and system state. Anti-forensic techniques are active efforts to defeat forensic examination, whereas the presence of a mutex actually provides evidence of execution and can be detected by forensic tools. Consequently, mutex creation is a behavioral indicator, not an anti-forensic technique.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which of the following is an example of an anti-forensics technique used to hide malicious activity?

easy
  • ✓ A.Timestomping
  • B.Running a sandbox
  • C.Creating a mutex
  • D.Generating a hash

Why A: Timestomping is an anti-forensics technique that deliberately modifies file timestamps (e.g., MAC times: Modified, Accessed, Created) using tools like `touch` on Linux or `SetFileTime` on Windows. By altering these timestamps, an attacker can hide the true timeline of malicious file creation, modification, or access, thereby evading forensic timeline analysis and making it appear that malicious activity occurred at a different time or was part of legitimate system operations.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.