Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 1

Malware Types, Components, and Distribution DFE Practice Questions (Page 6)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

39questions here
8free pages
3concepts

Questions 26–30

  1. 26application · medium

    During a malware analysis, you observe that a sample creates a scheduled task to run a script every hour. The script periodically downloads a small file from a remote server and executes it in memory. Which malware components are demonstrated?

    Select an answer first
  2. 27application · medium

    A forensic analyst is investigating a system that is part of a botnet. The malware on the system receives commands from a central server and participates in distributed denial-of-service (DDoS) attacks. The malware also has a mechanism to update itself from the server. Which malware type and component are demonstrated?

    Select an answer first
  3. 28expert · hard

    During an incident response, you find that malware entered the network via a malicious email attachment. Once executed, it used a Windows vulnerability to escalate privileges, then modified the registry to maintain persistence, and finally downloaded a payload that encrypted files and demanded a ransom. Which set of components and malware type is demonstrated?

    Select an answer first
  4. 29foundation · easy

    Which malware component is specifically designed to avoid detection by antivirus software and forensic tools, often by hiding processes, files, or registry entries?

    Select an answer first
  5. 30foundation · easy

    Which type of malware is primarily characterized by encrypting a victim's files and demanding payment to restore access?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.