
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 2
Malware Forensics CHFI Practice Questions (Page 1)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
55questions here
11free pages
11concepts
Questions 1–5
- 1
A malware analyst is reverse engineering a binary that uses a string-encryption routine. The analyst has identified the routine but it is called many times with different arguments. What is the most efficient way to extract all decrypted strings?
Select an answer first - 2
A malware analyst is reverse engineering a sample that uses a custom packer. The analyst has identified the unpacking routine and wants to dump the unpacked binary from memory. However, the malware has anti-dump protections that detect when a debugger is attached. Which technique is most effective for obtaining the unpacked binary?
Select an answer first - 3
Which of the following tools is primarily used for reverse engineering malware by allowing an analyst to step through the code instruction by instruction?
Select an answer first - 4
Which of the following is an example of a malware evasion technique?
Select an answer first - 5
A forensic analyst received a suspicious executable from an incident response team. The file is packed with a custom packer, and the analyst needs to identify the original import table and any embedded strings without executing the sample. Which approach should the analyst use first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.