312-49V11 · Question #179
In a digital forensics investigation, persistent malware is discovered on a compromised system despite repeated attempts to remove it. The malware reinstalls itself upon system reboot, indicating…
The correct answer is A. To prevent future infections and ensure the long-term security of the system. This question maps directly to CHFI v11 objectives under Malware Forensics, specifically malware persistence mechanisms and behavior analysis. Persistent malware is designed to survive system reboots and removal attempts by embedding itself into startup locations, registry…
Question
In a digital forensics investigation, persistent malware is discovered on a compromised system despite repeated attempts to remove it. The malware reinstalls itself upon system reboot, indicating sophisticated persistence mechanisms. In digital forensics, why is identifying malware persistence important?
Options
- ATo prevent future infections and ensure the long-term security of the system
- BTo enhance system performance
- CTo determine the geographical origin of the malware
- DTo optimize network bandwidth and reduce latency
How the community answered
(36 responses)- A75% (27)
- B3% (1)
- C8% (3)
- D14% (5)
Explanation
This question maps directly to CHFI v11 objectives under Malware Forensics, specifically malware persistence mechanisms and behavior analysis. Persistent malware is designed to survive system reboots and removal attempts by embedding itself into startup locations, registry keys, scheduled tasks, services, boot sectors, or firmware. CHFI v11 emphasizes that identifying persistence mechanisms is a critical step in malware analysis and incident response. From a forensic perspective, understanding how malware maintains persistence allows investigators to fully eradicate the threat and prevent reinfection. If persistence artifacts are not identified and removed, the malware can continuously reinstall itself, rendering cleanup efforts ineffective and allowing attackers to maintain long-term access. CHFI v11 highlights registry- based persistence, startup folders, services, cron jobs, launch agents, and boot-level persistence as common techniques that must be analyzed. Additionally, identifying persistence helps investigators reconstruct the attack timeline, understand attacker intent, and determine the scope of compromise.
Topics
Community Discussion
No community discussion yet for this question.