
EC-CouncilDigital Forensics Essentials
Domain 7Objective 1
Malware Types, Components, and Distribution DFE Practice Questions (Page 5)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
3concepts
Questions 21–25
- 21
An analyst is examining a malware sample that spreads by copying itself to network shares and also modifies the hosts file to redirect traffic. Which two malware components are demonstrated?
Select an answer first - 22
A forensic analyst is examining a USB drive found in a company parking lot. The drive contains an autorun.inf file and a hidden executable. When plugged in, the executable runs automatically and installs a backdoor. Which malware component and distribution vector are demonstrated?
Select an answer first - 23
A forensic examiner is analyzing three malware samples. Sample A spreads by copying itself to network shares. Sample B disguises itself as a legitimate application and creates a backdoor. Sample C encrypts files and demands payment. Which classification is correct for each sample?
Select an answer first - 24
An incident response team is analyzing a malware infection. The malware was delivered via a malicious email attachment. Once executed, it created a scheduled task to maintain persistence and then downloaded a payload that stole credentials. The malware also used a technique to avoid detection by security software. Which components are demonstrated?
Select an answer first - 25
A forensic examiner is analyzing a system where the user downloaded a 'free screensaver' that, when installed, also installed a toolbar that displayed unwanted advertisements and collected browsing habits. The user did not notice the toolbar installation because it was bundled with the screensaver. Which malware type best describes the toolbar?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.