Which category includes artifacts found on the host such as filenames, file hashes, registry keys, DLLs, and mutex?

Prepare for the Certified Ethical Hacker Version 11 Exam with a comprehensive test featuring flashcards and multiple choice questions, each accompanied by hints and explanations to ensure a thorough understanding. Ace your ethical hacking exam with confidence!

Multiple Choice

Which category includes artifacts found on the host such as filenames, file hashes, registry keys, DLLs, and mutex?

Explanation:
Artifacts that exist on the endpoint—like filenames, file hashes, registry keys, loaded DLLs, and mutex objects—are host-based indicators. They are static evidence gathered from the victim’s machine that can reveal what malware or unauthorized software is present, how it persists, and how it interacts with the system. File hashes help identify known malicious files, registry keys can show persistence or autostart mechanisms, DLLs indicate libraries loaded into processes, and a mutex can signal coordinated actions or a single-instance malware check. Behavioral indicators, by comparison, describe actions or patterns over time (such as unusual processes or network traffic), not the specific artifacts stored on the host. So these artifacts on the host fit the category of host-based indicators.

Artifacts that exist on the endpoint—like filenames, file hashes, registry keys, loaded DLLs, and mutex objects—are host-based indicators. They are static evidence gathered from the victim’s machine that can reveal what malware or unauthorized software is present, how it persists, and how it interacts with the system. File hashes help identify known malicious files, registry keys can show persistence or autostart mechanisms, DLLs indicate libraries loaded into processes, and a mutex can signal coordinated actions or a single-instance malware check. Behavioral indicators, by comparison, describe actions or patterns over time (such as unusual processes or network traffic), not the specific artifacts stored on the host. So these artifacts on the host fit the category of host-based indicators.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy