
EC-CouncilDigital Forensics Essentials
Domain 7Objective 3
Static Malware Analysis DFE Practice Questions (Page 3)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
9concepts
Questions 11–15
- 11
While analyzing a Windows PE file, an analyst notices that the section named .text has write permissions (characteristics include 0xE0000020). What should the analyst consider?
Select an answer first - 12
A security operations center receives a suspicious file from an employee. The analyst computes an MD5 hash and finds it matches a known malware sample in a threat intelligence feed. However, the file's SHA-256 hash does not match any known sample. What is the most likely explanation?
Select an answer first - 13
While inspecting a suspicious PE file, you notice that the import table contains only two functions: LoadLibraryA and GetProcAddress. The file also has a section named .UPX0 with unusual characteristics. What does this combination most likely indicate?
Select an answer first - 14
A security analyst receives a suspicious executable from a user. The analyst computes a SHA-256 hash and submits it to a public malware repository, which returns no matches. The analyst then runs the file through several antivirus engines; only one engine flags it as malware. What is the most appropriate next step?
Select an answer first - 15
A forensic analyst is examining a suspicious executable and finds that it imports InternetOpenA, HttpSendRequestA, and CreateFileA. What is the most reasonable inference about the executable's functionality?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.