
EC-CouncilDigital Forensics Essentials
Domain 7Objective 4
Dynamic Malware Analysis DFE Practice Questions (Page 2)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
6concepts
Questions 6–10
- 6
Why is it important to take a snapshot of a virtual machine before executing malware?
Select an answer first - 7
An analyst has completed dynamic analysis of a multi-stage malware. The first stage downloads a second stage from a URL, and the second stage installs a driver. The analyst needs to write a report that will help the incident response team contain the malware. Which information is most critical to include?
Select an answer first - 8
After completing dynamic analysis of a banking trojan, an analyst must produce a report for the incident response team. The report should include indicators of compromise (IOCs) and behavioral observations. Which set of items should the analyst include?
Select an answer first - 9
An analyst is preparing a VM for dynamic analysis of a rootkit. The analyst wants to ensure that the VM can be restored to a clean state after the analysis. Which step is essential before executing the malware?
Select an answer first - 10
An analyst is analyzing a sample that is suspected of using a rootkit to hide its processes. The analyst has Process Explorer and Process Monitor available. The analyst notices that the malware creates a process that is not visible in Process Explorer. Which action should the analyst take to confirm the hidden process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.