Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 4Objective 2

Malware Forensics CHFI Practice Questions (Page 4)

Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.

55questions here
11free pages
11concepts

Questions 16–20

  1. 16application · medium

    During a forensic investigation, an analyst discovers that a malicious executable has been persisting across reboots. The analyst wants to identify the persistence mechanism without executing the malware again. Which action is most effective?

    Select an answer first
  2. 17application · medium

    A forensic investigator is analyzing a suspicious document that contains an embedded macro. The investigator wants to extract the macro code without opening the document in a word processor. Which tool or technique is most appropriate?

    Select an answer first
  3. 18application · medium

    During a malware investigation, an analyst needs to preserve a memory dump from a compromised Windows system for later analysis. Which tool is most appropriate for this task?

    Select an answer first
  4. 19foundation · easy

    Which of the following is a common persistence mechanism used by malware on Windows systems?

    Select an answer first
  5. 20foundation · easy

    Which of the following activities would be observed during dynamic analysis of malware in a sandbox?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.