CHFI OS and Network Forensics Practice Question
Which TWO of the following are common persistence mechanisms used by malware on Windows systems? (Select two.)
⚠ Common exam trap
EC-Council often tests the distinction between artifacts of execution (like Prefetch and LNK files) and actual persistence mechanisms that cause automatic re-execution, leading candidates to mistakenly select options that indicate malware ran but do not ensure it runs again.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scheduled Tasks
Scheduled Tasks (C) are a common persistence mechanism because malware can register a task via schtasks.exe or the Task Scheduler COM API to execute a payload at logon, on a schedule, or on system events, surviving reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that Windows processes at user logon, so malware placed there launches automatically each session. The other options are forensic artifacts rather than persistence methods: USBSTOR records historical USB mass-storage connections, Prefetch files evidence program execution for performance, and LNK files are shortcut artifacts often used for initial execution or user bait, not for maintaining persistence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
USBSTOR registry key
Why it's wrong here
The USBSTOR registry key records previously connected USB storage devices, supporting forensic device-history analysis rather than malware persistence. It is tempting because it is a genuine registry artefact, but Windows does not launch code from it at boot or logon. It would be the correct answer for tracing USB device usage.
- ✗
Prefetch files
Why it's wrong here
Prefetch files record execution history for forensic timeline reconstruction; they are artefacts, not persistence. They are tempting because malware touches them, but Windows does not read Prefetch to relaunch programs, so deleting them does not remove persistence. They would be the right answer to a question about evidence of program execution.
- ✓
Scheduled Tasks
Why this is correct
Scheduled Tasks let malware register a trigger that launches its payload at logon, boot or on a timer, surviving reboots and often masquerading as legitimate maintenance. This satisfies the persistence requirement by re-establishing execution without user interaction.
- ✗
LNK files
Why it's wrong here
LNK files are shortcut artefacts that document recent file and application access for forensic analysis; Windows does not execute them at logon to maintain malware. They are tempting because malicious shortcuts can be placed in Startup, but the LNK format itself is not the persistence mechanism — the Startup folder entry is.
- ✓
Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run)
Why this is correct
Run keys under HKLM and HKCU cause Windows to launch listed programs at user logon, so malware written there survives reboots without a service. This satisfies the persistence requirement by re-executing the payload automatically each session.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.