Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 3

Static Malware Analysis DFE Practice Questions (Page 3)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

51questions here
11free pages
9concepts

Questions 11–15

  1. 11application · medium

    While analyzing a Windows PE file, an analyst notices that the section named .text has write permissions (characteristics include 0xE0000020). What should the analyst consider?

    Select an answer first
  2. 12application · medium

    A security operations center receives a suspicious file from an employee. The analyst computes an MD5 hash and finds it matches a known malware sample in a threat intelligence feed. However, the file's SHA-256 hash does not match any known sample. What is the most likely explanation?

    Select an answer first
  3. 13application · medium

    While inspecting a suspicious PE file, you notice that the import table contains only two functions: LoadLibraryA and GetProcAddress. The file also has a section named .UPX0 with unusual characteristics. What does this combination most likely indicate?

    Select an answer first
  4. 14application · medium

    A security analyst receives a suspicious executable from a user. The analyst computes a SHA-256 hash and submits it to a public malware repository, which returns no matches. The analyst then runs the file through several antivirus engines; only one engine flags it as malware. What is the most appropriate next step?

    Select an answer first
  5. 15application · medium

    A forensic analyst is examining a suspicious executable and finds that it imports InternetOpenA, HttpSendRequestA, and CreateFileA. What is the most reasonable inference about the executable's functionality?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.