
EC-CouncilCertified Ethical Hacker
Domain 3Objective 7
Malware Threats (Trojans, Viruses, Ransomware) CEH Practice Questions (Page 3)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 11–15
- 11
A user downloads a cracked software installer from an untrusted website. After running it, the user notices that their system is sending sensitive documents to an external server. Which type of malware is most likely installed, and what is its primary purpose?
Select an answer first - 12
A security analyst discovers a malicious executable that disguises itself as a legitimate PDF viewer. When a user opens the file, it installs a backdoor and allows remote access. Which type of malware is this?
Select an answer first - 13
Which of the following is an effective preventive measure against ransomware?
Select an answer first - 14
A security team discovers that a piece of malware changes its code each time it replicates, but the changes are only in the decryption routine while the payload remains the same. Which evasion technique is being used, and which detection approach is most likely to succeed?
Select an answer first - 15
During a forensic investigation, an analyst finds that a trojan was delivered via a phishing email, installed itself in the user's AppData folder, and created a service to run at startup. Which stage of the malware lifecycle is the service creation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.