
EC-CouncilCertified Ethical Hacker
Domain 3Objective 8
Malware Analysis and Countermeasures CEH Practice Questions (Page 7)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
Questions 31–35
- 31
A security team is analyzing a sophisticated malware sample. The team has limited time and resources. They need to determine the malware's capabilities and impact. Which analysis strategy is most efficient?
Select an answer first - 32
A security analyst must determine whether a suspicious file is malicious. The analyst has limited time and needs a quick initial assessment. The file appears to be a Windows executable. Which approach provides the fastest initial indication of maliciousness?
Select an answer first - 33
A malware analyst is using a debugger to analyze a packed binary. The binary unpacks itself at runtime. Which technique should the analyst use to observe the unpacked code?
Select an answer first - 34
A malware analyst is examining a suspicious document file that is believed to contain a macro-based dropper. The analyst wants to extract the embedded macro without executing it. Which tool is most appropriate?
Select an answer first - 35
A security team is analyzing a suspected keylogger. They need to observe what data it captures and where it sends it. The analysis environment must be isolated from the production network. Which combination of tools and setup is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.