
EC-CouncilDigital Forensics Essentials
Domain 7Objective 2
Malware Forensics Fundamentals DFE Practice Questions (Page 9)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
6concepts
Questions 41–45
- 41
What is the primary purpose of malware forensics within the digital forensics process?
Select an answer first - 42
A forensic team is investigating a malware infection on a critical production server. The server cannot be taken offline for more than 30 minutes due to business requirements. The team needs to preserve volatile evidence (e.g., memory, running processes) and then perform a forensic analysis. Which approach best balances the need for evidence preservation with the operational constraint?
Select an answer first - 43
A forensic investigator is handling a malware case that involves a cloud-hosted server. The server is located in a different jurisdiction than the investigator's office. The investigator needs to collect evidence while complying with legal and privacy regulations. Which action is most appropriate?
Select an answer first - 44
A malware analyst is tasked with determining whether a suspicious file is malicious. The analyst has limited time and needs a quick initial assessment. Which approach provides the fastest and least resource-intensive method to get an initial indication?
Select an answer first - 45
A company has identified a malware infection on a server. The incident response team needs to contain the infection while preserving evidence for a forensic investigation. Which action should be taken FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.