nerdexam
EC-Council

312-49V11 · Question #179

In a digital forensics investigation, persistent malware is discovered on a compromised system despite repeated attempts to remove it. The malware reinstalls itself upon system reboot, indicating…

The correct answer is A. To prevent future infections and ensure the long-term security of the system. This question maps directly to CHFI v11 objectives under Malware Forensics, specifically malware persistence mechanisms and behavior analysis. Persistent malware is designed to survive system reboots and removal attempts by embedding itself into startup locations, registry…

Malware Forensics

Question

In a digital forensics investigation, persistent malware is discovered on a compromised system despite repeated attempts to remove it. The malware reinstalls itself upon system reboot, indicating sophisticated persistence mechanisms. In digital forensics, why is identifying malware persistence important?

Options

  • ATo prevent future infections and ensure the long-term security of the system
  • BTo enhance system performance
  • CTo determine the geographical origin of the malware
  • DTo optimize network bandwidth and reduce latency

How the community answered

(36 responses)
  • A
    75% (27)
  • B
    3% (1)
  • C
    8% (3)
  • D
    14% (5)

Explanation

This question maps directly to CHFI v11 objectives under Malware Forensics, specifically malware persistence mechanisms and behavior analysis. Persistent malware is designed to survive system reboots and removal attempts by embedding itself into startup locations, registry keys, scheduled tasks, services, boot sectors, or firmware. CHFI v11 emphasizes that identifying persistence mechanisms is a critical step in malware analysis and incident response. From a forensic perspective, understanding how malware maintains persistence allows investigators to fully eradicate the threat and prevent reinfection. If persistence artifacts are not identified and removed, the malware can continuously reinstall itself, rendering cleanup efforts ineffective and allowing attackers to maintain long-term access. CHFI v11 highlights registry- based persistence, startup folders, services, cron jobs, launch agents, and boot-level persistence as common techniques that must be analyzed. Additionally, identifying persistence helps investigators reconstruct the attack timeline, understand attacker intent, and determine the scope of compromise.

Topics

#malware persistence#malware forensics#persistence mechanisms#incident response

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice