Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 3

Static Malware Analysis DFE Practice Questions (Page 10)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

51questions here
11free pages
9concepts

Questions 46–50

  1. 46expert · hard

    A malware analyst is examining a suspicious executable. Detect It Easy reports that the file is packed with a custom packer, and the entropy of the .text section is 7.8. The analyst also notices that the file has an unusual number of sections and that the import table is minimal. The analyst must decide whether to attempt manual unpacking or use a different approach. What is the most appropriate next step?

    Select an answer first
  2. 47foundation · easy

    Why does packing or obfuscation complicate static malware analysis?

    Select an answer first
  3. 48foundation · easy

    What type of data can be found in the resource section (.rsrc) of a PE file?

    Select an answer first
  4. 49application · easy

    A junior analyst is asked to perform static analysis on a suspicious file. The analyst wants to avoid executing the file. Which activity is consistent with static analysis?

    Select an answer first
  5. 50application · medium

    A malware analyst is examining a suspicious executable and extracts strings. The strings include 'http://example.com/payload.bin', 'C:\Users\Public\file.exe', and 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run'. What is the most likely functionality of the malware?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.