Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 4

Dynamic Malware Analysis DFE Practice Questions (Page 5)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

45questions here
9free pages
6concepts

Questions 21–25

  1. 21application · medium

    During dynamic analysis, an analyst captures network traffic and sees that the malware is communicating with an IP address on port 443 using TLS. The analyst wants to determine the content of the communication. Which approach is most appropriate?

    Select an answer first
  2. 22foundation · easy

    What is an indicator of compromise (IoC) in a malware analysis report?

    Select an answer first
  3. 23foundation · easy

    What type of information can TCPView provide during dynamic malware analysis?

    Select an answer first
  4. 24application · medium

    While analyzing a ransomware sample in a sandbox, an analyst notices that the malware checks for the presence of a debugger and then delays its execution if one is detected. The analyst also observes that the malware writes to the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Which two behaviors should the analyst document in the report?

    Select an answer first
  5. 25foundation · easy

    Which of the following is an example of a persistence mechanism that malware might use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.