300-215 · Question #130
Refer to the exhibit. Which registry key is suspected to be used by an attacker to establish persistence?
The correct answer is A. HKCU\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON. The Winlogon Shell registry setting controls which executable is launched as the user’s shell at logon. Modifying this value to launch a user-profile malware binary (while still starting explorer.exe) is a common persistence mechanism because it re-executes the malicious file…
Question
Refer to the exhibit. Which registry key is suspected to be used by an attacker to establish persistence?
Exhibit
Options
- AHKCU\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
- BUSERS\S-1-5-21-3467368655-986044752-3166994390-500*\START.EXE
- CHKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\AUTORUN
- DUSERS\S-5-21-0123456789-986044752-3166994390-500*\ZONEMAP
How the community answered
(51 responses)- A88% (45)
- B6% (3)
- C4% (2)
- D2% (1)
Explanation
The Winlogon Shell registry setting controls which executable is launched as the user’s shell at logon. Modifying this value to launch a user-profile malware binary (while still starting explorer.exe) is a common persistence mechanism because it re-executes the malicious file each time the user signs in.
Topics
Community Discussion
No community discussion yet for this question.
