
EC-CouncilDigital Forensics Essentials
Domain 7Objective 1
Malware Types, Components, and Distribution DFE Practice Questions (Page 7)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
39questions here
8free pages
3concepts
Questions 31–35
- 31
A security analyst is reviewing a series of incidents. In one, a user downloaded a file from a peer-to-peer network that turned out to be a Trojan. In another, a server was compromised via an unpatched vulnerability and joined a botnet. In a third, a user's system had a rootkit that hid a keylogger. Which classification best describes the malware types involved?
Select an answer first - 32
In malware analysis, which term refers to the malicious action that a malware performs after it has successfully infected a system, such as deleting files, stealing data, or encrypting files?
Select an answer first - 33
A security team notices that multiple employees have been infected with the same malware after visiting a popular online forum. The forum administrators confirm that they did not intentionally host malware, but an attacker had injected malicious JavaScript into the site's ad server. Which distribution vector best describes this attack?
Select an answer first - 34
A forensic analyst is examining a system where the user clicked a link in a phishing email. The analyst finds a file that, when executed, drops a second file into the startup folder and then immediately deletes itself from the disk. The dropped file establishes a connection to a command-and-control server and waits for instructions. Which malware type best describes the dropped file?
Select an answer first - 35
A forensic team is analyzing a malware infection that occurred in a segmented network. The initial entry was a USB drive left in the parking lot. The malware then used a known vulnerability in the SMB protocol to move laterally to other servers. On one server, it installed a driver that hides its processes. Which combination of components and vectors is present?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.