Courseiva
OS and Network Forensics →easyMultiple Select

CHFI OS and Network Forensics Practice Question

Which TWO of the following are persistence mechanisms commonly found in Windows forensics? (Select two.)

⚠ Common exam trap

EC-Council often tests the distinction between forensic artifacts that record past activity (like Jump lists, ShellBags, and Prefetch) versus those that actively cause code execution on system startup (like Scheduled Tasks and Registry Run keys), leading candidates to confuse evidence of execution with persistence mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled Tasks

Scheduled Tasks (C) are a well-known Windows persistence mechanism because an attacker can register a task via schtasks.exe or the Task Scheduler that launches malware at logon, on a schedule, or on system events, and these tasks survive reboots. Registry Run keys (E), such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents, are classic autostart locations that execute listed programs at user logon, making them a common persistence technique. By contrast, Jump lists (A) are artifacts recording recently accessed files and applications for forensic reconstruction, not autostart mechanisms. ShellBags (B) store folder view settings and window preferences in the registry to show user navigation history, and Prefetch files (D) are performance artifacts in C:\Windows\Prefetch that record executed program traces, neither of which causes programs to run automatically at startup.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Jump lists

    Why it's wrong here

    Jump lists are user interface artifacts stored under %APPDATA%\Microsoft\Windows\Recent as .automaticDestinations-ms and .customDestinations-ms files, recording recently opened documents and application-specific tasks. They are not a persistence mechanism because they contain no auto-start or code-execution logic; at most they can be abused in LNK shortcut attacks if opened by a user. In forensic triage, jump lists provide evidence of user file access, not of a program's ability to survive reboot.

  • ✗

    ShellBags

    Why it's wrong here

    ShellBags persist in the Registry under HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags and BagMRU, where Explorer caches per-folder display settings such as window position, icon size, and sort order. Although their name and registry location suggest persistence, they are not used to launch code; they store state for the Windows GUI shell only. For investigators, ShellBags help reconstruct a user's browsing history across file shares and mapped drives, but malware cannot use them as a reliable autostart point.

  • ✓

    Scheduled Tasks

    Why this is correct

    Scheduled Tasks are a built-in persistence mechanism managed by the Task Scheduler service (svchost.exe running Schedule) and exposed via schtasks.exe or the XML-based task folders under %SystemRoot%\System32\Tasks. An attacker can create a task with a trigger such as logon, system startup, idle, or a specific event, and specify an action that executes a malicious binary, often with SYSTEM privileges if configured. Unlike jump lists or prefetch files, scheduled tasks are first-class operating system facilities for executing code at defined times, making them a common and persistent malware foothold.

  • ✗

    Prefetch files

    Why it's wrong here

    Prefetch files (.pf) in C:\Windows\Prefetch are generated whenever an application runs, recording the application name, run count, last run time, and a hash of the full path so Windows can optimize subsequent start-ups by preloading pages. They are not a persistence mechanism because the data is read by the memory manager to speed up program launch, not to launch programs automatically; if an executable is deleted, its prefetch entry cannot restart it. Forensic examiners use Prefetch to identify that a malicious binary executed on a system, not as evidence of an autostart entry.

  • ✓

    Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run)

    Why this is correct

    Registry Run keys such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run define the most elementary Windows autostart persistence: every value string is treated as an executable path that Explorer launches when the user logs in. The HKLM variant persists for all users and typically requires administrative rights to write, whereas HKCU can be modified by the user without elevation, a distinction attackers regularly exploit. This mechanism is so widely abused that forensic analysis always checks these keys and related RunOnce, StartupApproved, and Winlogon values.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.