
EC-CouncilDigital Forensics Essentials
Domain 7Objective 4
Dynamic Malware Analysis DFE Practice Questions (Page 9)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
6concepts
Questions 41–45
- 41
An analyst is using Process Monitor to observe a malware sample. The analyst wants to filter the output to show only file system activity related to a specific directory. Which filter criteria should the analyst apply?
Select an answer first - 42
During dynamic analysis, an analyst observes that the malware creates a mutex named 'Global\MyAppMutex' and then spawns a child process that runs with elevated privileges. Which two behaviors should the analyst note in the report?
Select an answer first - 43
What is the primary function of Regshot in dynamic malware analysis?
Select an answer first - 44
What is an anti-analysis technique that malware might use to hinder dynamic analysis?
Select an answer first - 45
An analyst has completed dynamic analysis of a keylogger and needs to document the findings. Which section should be included in the report to describe the malware's behavior in a structured way?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.