
EC-CouncilDigital Forensics Essentials
Domain 7Objective 2
Malware Forensics Fundamentals DFE Practice Questions (Page 1)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
6concepts
Questions 1–5
- 1
An incident responder is analyzing a system infected with malware that hides its processes by using a rootkit technique. The malware also modifies system files to avoid detection. Which two behaviors are being exhibited?
Select an answer first - 2
Which activity is a core component of malware forensics?
Select an answer first - 3
A forensic analyst is examining a Windows workstation that was infected after a user clicked a link in a phishing email. The analyst observes that the malware creates a scheduled task that runs a PowerShell script every time the user logs on, and the script periodically sends HTTP POST requests to a remote server. Which malware behavior is the analyst most directly observing?
Select an answer first - 4
A security analyst notices that a workstation is making repeated outbound connections to an IP address known to be a command-and-control server. The malware was likely delivered via a malicious email attachment. Which two indicators support this infection vector?
Select an answer first - 5
During a malware investigation, an analyst observes that a suspicious process injects code into a legitimate system process (e.g., svchost.exe) and then creates a scheduled task to run a script at system startup. Which two behaviors are being exhibited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.