nerdexam
Cisco

300-215 · Question #130

Refer to the exhibit. Which registry key is suspected to be used by an attacker to establish persistence?

The correct answer is A. HKCU\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON. The Winlogon Shell registry setting controls which executable is launched as the user’s shell at logon. Modifying this value to launch a user-profile malware binary (while still starting explorer.exe) is a common persistence mechanism because it re-executes the malicious file…

Submitted by femi9· Mar 6, 2026Forensics Techniques

Question

Refer to the exhibit. Which registry key is suspected to be used by an attacker to establish persistence?

Exhibit

300-215 question #130 exhibit

Options

  • AHKCU\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
  • BUSERS\S-1-5-21-3467368655-986044752-3166994390-500*\START.EXE
  • CHKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\AUTORUN
  • DUSERS\S-5-21-0123456789-986044752-3166994390-500*\ZONEMAP

How the community answered

(51 responses)
  • A
    88% (45)
  • B
    6% (3)
  • C
    4% (2)
  • D
    2% (1)

Explanation

The Winlogon Shell registry setting controls which executable is launched as the user’s shell at logon. Modifying this value to launch a user-profile malware binary (while still starting explorer.exe) is a common persistence mechanism because it re-executes the malicious file each time the user signs in.

Topics

#Windows forensics#Registry analysis#Persistence mechanisms#Attacker techniques

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice