
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 2
Malware Forensics CHFI Practice Questions (Page 6)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
55questions here
11free pages
11concepts
Questions 26–30
- 26
An incident responder is analyzing a memory dump from a compromised server. The responder suspects that the malware injected code into a legitimate process. Which technique is most effective for identifying the injected code?
Select an answer first - 27
A malware analyst is about to execute a suspicious binary in a controlled lab. The analyst needs to observe file system changes, registry modifications, and network connections made by the sample. Which setup best satisfies these requirements?
Select an answer first - 28
What is the primary purpose of dynamic malware analysis?
Select an answer first - 29
A malware analyst is examining a network capture from a sandbox. The malware is making DNS queries to a domain that changes frequently. What is the most likely purpose of this behavior?
Select an answer first - 30
An analyst is investigating a malware sample that uses domain generation algorithms (DGAs) to communicate with its command-and-control server. The analyst has captured network traffic from a sandbox execution, but the malware only made a few DNS queries and did not establish a connection. The analyst needs to identify the C2 domain for blocking. Which technique is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.