
EC-CouncilDigital Forensics Essentials
Domain 7Objective 2
Malware Forensics Fundamentals DFE Practice Questions (Page 5)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
6concepts
Questions 21–25
- 21
A security analyst is investigating a malware infection that appears to have originated from a malicious website. The malware is a trojan that downloads additional payloads from a C2 server. Which two pieces of evidence would most strongly support the malicious website as the infection vector?
Select an answer first - 22
A malware analyst is investigating a suspicious executable found on a compromised workstation. The analyst needs to determine what the executable does without risking further infection of the analysis environment. Which approach should the analyst use?
Select an answer first - 23
Which step in a malware forensics investigation involves isolating the infected system from the network to prevent the malware from spreading?
Select an answer first - 24
A forensic analyst is documenting a malware investigation for a court case. The analyst must ensure that the evidence is admissible. Which practice is most important?
Select an answer first - 25
A forensic analyst is examining a memory dump from a compromised server. The analyst finds that a malicious DLL has been loaded into the address space of a legitimate service process. The DLL is not listed in the service's normal module list. Which malware behavior is this evidence of?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.