
EC-CouncilComputer Hacking Forensic Investigator
Domain 4Objective 2
Malware Forensics CHFI Practice Questions (Page 9)
Part of the Network and Malware Forensics domain, which makes up ~15% of our current practice bank.
55questions here
11free pages
11concepts
Questions 41–45
- 41
A malware analyst is executing a sample in a sandbox. The sample detects that it is running in a virtual machine and refuses to execute its malicious payload. The analyst needs to observe the payload's behavior. Which action is most likely to succeed?
Select an answer first - 42
A reverse engineer is analyzing a malware sample that uses a custom obfuscation technique. The code is heavily obfuscated and the analyst needs to understand the malware's logic. Which approach is most effective?
Select an answer first - 43
What is the primary focus of malware code analysis?
Select an answer first - 44
A malware sample uses a custom packer that also contains anti-VM and anti-debugging checks. The analyst needs to unpack the sample and analyze its code, but the sample refuses to run in the sandbox. Which approach is most likely to succeed?
Select an answer first - 45
What is the purpose of extracting malware artifacts during an investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.