
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 2
Malware Forensics CHFI Practice Questions (Page 7)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
55questions here
11free pages
11concepts
Questions 31–35
- 31
An analyst is investigating a rootkit that hides its processes and files. The analyst needs to extract the rootkit's artifacts from a live system. Which approach is most likely to succeed?
Select an answer first - 32
What is the purpose of anti-debugging techniques used by malware?
Select an answer first - 33
While analyzing network traffic from a malware sandbox, an analyst observes periodic HTTPS connections to a domain that has a low reputation. The payload is encrypted. What is the most appropriate next step to determine if this is command-and-control (C2) traffic?
Select an answer first - 34
During reverse engineering of a malware sample, an analyst notices that the binary contains several opaque predicates and uses a junk-code insertion technique. What is the primary purpose of these obfuscation techniques?
Select an answer first - 35
What is the primary purpose of analyzing network traffic generated by malware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.