
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 2
Malware Forensics CHFI Practice Questions (Page 3)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
55questions here
11free pages
11concepts
Questions 11–15
- 11
A malware sample is known to check for the presence of a virtual machine by looking for specific hardware strings. The analyst needs to run the sample in a sandbox to observe its behavior. Which of the following is the most effective way to avoid triggering the anti-VM check?
Select an answer first - 12
Which of the following tools is commonly used for static analysis of a Windows executable to view its PE header and imported functions?
Select an answer first - 13
During dynamic analysis, a malware sample uses a non-standard port (e.g., TCP 4444) to communicate with an external IP. The analyst suspects a reverse shell. What is the most definitive way to confirm this?
Select an answer first - 14
Which of the following tools is used to monitor file system, registry, and process activity in real time during dynamic malware analysis?
Select an answer first - 15
A forensic analyst receives a suspicious executable from an internal user. The file has a valid digital signature from a known software vendor, but the user reports unusual network activity after running it. The analyst needs to determine whether the file is malicious without executing it. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.