Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 3

Static Malware Analysis DFE Practice Questions (Page 2)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

51questions here
11free pages
9concepts

Questions 6–10

  1. 6application · medium

    An analyst is examining the resources of a suspicious executable and finds a custom resource type named 'DATA' that contains a large binary blob. What is the most appropriate action?

    Select an answer first
  2. 7application · medium

    During static analysis of a suspicious executable, you extract the version information resource and find the company name 'Microsoft Corporation' and the product name 'Windows Update'. However, the file's digital signature is invalid. What is the most likely explanation?

    Select an answer first
  3. 8expert · hard

    A malware analyst is examining a suspicious executable and extracts a resource that contains a string that looks like a base64-encoded blob. The analyst decodes it and finds a URL. However, the URL is not present in the binary's strings. What is the most likely reason?

    Select an answer first
  4. 9foundation · easy

    What is the purpose of the PE header in a Windows executable?

    Select an answer first
  5. 10foundation · easy

    What is the primary characteristic of static malware analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.