Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 2

Forensic Investigation and Malware Analysis CSA Practice Questions (Page 6)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

55questions here
11free pages
10concepts

Questions 26–30

  1. 26application · medium

    A SOC analyst is setting up a dynamic malware analysis environment. The malware is known to detect virtual machines and refuse to run. Which configuration is most likely to help the malware execute successfully?

    Select an answer first
  2. 27application · medium

    During static analysis of a malware sample, the analyst notices that the file's import table only contains LoadLibrary and GetProcAddress. The file size is unusually large for the number of imports. What is the most likely explanation?

    Select an answer first
  3. 28foundation · easy

    When collecting digital evidence from a live system, which type of data should be collected FIRST to avoid losing it?

    Select an answer first
  4. 29foundation · easy

    Which of the following is a key advantage of dynamic malware analysis over static analysis?

    Select an answer first
  5. 30expert · hard

    During dynamic analysis of a malware sample, the analyst observes that the sample makes DNS queries to a domain that changes every few minutes. The analyst suspects the malware uses domain generation algorithms (DGAs). Which approach is most effective for identifying the C2 infrastructure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.