
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 2
Malware Forensics CHFI Practice Questions (Page 4)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
55questions here
11free pages
11concepts
Questions 16–20
- 16
During a forensic investigation, an analyst discovers that a malicious executable has been persisting across reboots. The analyst wants to identify the persistence mechanism without executing the malware again. Which action is most effective?
Select an answer first - 17
A forensic investigator is analyzing a suspicious document that contains an embedded macro. The investigator wants to extract the macro code without opening the document in a word processor. Which tool or technique is most appropriate?
Select an answer first - 18
During a malware investigation, an analyst needs to preserve a memory dump from a compromised Windows system for later analysis. Which tool is most appropriate for this task?
Select an answer first - 19
Which of the following is a common persistence mechanism used by malware on Windows systems?
Select an answer first - 20
Which of the following activities would be observed during dynamic analysis of malware in a sandbox?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.