Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 4Objective 2

Malware Forensics CHFI Practice Questions (Page 7)

Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.

55questions here
11free pages
11concepts

Questions 31–35

  1. 31expert · hard

    An analyst is investigating a rootkit that hides its processes and files. The analyst needs to extract the rootkit's artifacts from a live system. Which approach is most likely to succeed?

    Select an answer first
  2. 32foundation · easy

    What is the purpose of anti-debugging techniques used by malware?

    Select an answer first
  3. 33application · medium

    While analyzing network traffic from a malware sandbox, an analyst observes periodic HTTPS connections to a domain that has a low reputation. The payload is encrypted. What is the most appropriate next step to determine if this is command-and-control (C2) traffic?

    Select an answer first
  4. 34application · medium

    During reverse engineering of a malware sample, an analyst notices that the binary contains several opaque predicates and uses a junk-code insertion technique. What is the primary purpose of these obfuscation techniques?

    Select an answer first
  5. 35foundation · easy

    What is the primary purpose of analyzing network traffic generated by malware?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.