312-50 exam dumps

312-50 practice question 164 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 164

Single answer▪ Trojan Concepts

During an internal security assessment, you are asked to determine whether a Windows workstation is infected with a Remote Access Trojan (RAT) that survives reboots and gives an attacker ongoing control. The user reports periodic system slowdowns, but antivirus has not generated any alerts. Which action would provide the strongest host-based evidence of a Trojan maintaining persistence on the system?

  1. A

    Review Windows startup persistence locations such as Run registry keys, Startup folders, and scheduled tasks for suspicious executables or scripts

  2. B

    Check whether the workstation responds to ICMP echo requests from other hosts on the network

  3. C

    Verify that the system has the latest Microsoft security patches installed

  4. D

    Compare the workstation's MAC address against the authorized hardware inventory

Show answer and explanation

Correct answer: A

Explanation

Trojan concepts in CEH commonly include understanding how Trojans are installed, how they maintain persistence, and how they can evade simple detection. A Remote Access Trojan is designed to provide ongoing unauthorized access, so persistence is a key indicator during host analysis. On Windows, common persistence points include registry keys such as HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run, Startup folders, services, and scheduled tasks. Reviewing these areas is aligned with practical incident response and malware triage methods. Microsoft documentation on startup apps, Task Scheduler, and Sysinternals tools such as Autoruns supports this approach, as Autoruns is widely used to enumerate common autostart extensibility points. In a real assessment, this host-based review would often be combined with process inspection, network connection review, hash validation, and EDR telemetry to confirm whether the suspicious entry is malicious.

  • A. Correct.

    Correct. A RAT or Trojan that survives reboot typically relies on persistence mechanisms such as registry Run keys, RunOnce entries, Startup folders, services, WMI event subscriptions, or scheduled tasks. Reviewing these locations for unusual binaries, scripts, or user-context executables is one of the most direct host-based ways to confirm Trojan persistence. In Windows environments, attackers commonly abuse these locations because they trigger execution automatically after login or system startup.

  • B. Incorrect.

    Incorrect. ICMP echo replies only indicate whether the host responds to ping; they do not provide meaningful evidence of Trojan persistence. A system may answer ICMP whether it is clean or infected, and many organizations block or rate-limit ICMP anyway. Choosing this option reflects the misconception that basic network reachability proves compromise.

  • C. Incorrect.

    Incorrect. Patch status is important for reducing exposure to malware, but being fully patched does not prove a Trojan is absent, and being unpatched does not prove a Trojan is present. This option addresses vulnerability management rather than confirming active malware persistence. A RAT may be installed through phishing, stolen credentials, or user execution even on a patched system.

  • D. Incorrect.

    Incorrect. Matching the MAC address to inventory can help with asset identification or detect rogue devices on a network, but it does not show whether malware is persisting on the endpoint. This option may seem reasonable in an asset-control context, but it does not investigate Trojan behavior or autostart mechanisms.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam