
EC-CouncilDigital Forensics Essentials
Domain 7Objective 3
Static Malware Analysis DFE Practice Questions (Page 6)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
9concepts
Questions 26–30
- 26
An analyst extracts strings from a malware sample and finds an IP address and a file path. What is the most reasonable interpretation?
Select an answer first - 27
Which part of a Portable Executable (PE) file contains information about the sections, such as their names and sizes?
Select an answer first - 28
Which property of a cryptographic hash makes it useful for file fingerprinting?
Select an answer first - 29
During static analysis of a malware sample, an analyst extracts the resources section and finds an embedded executable file. What is the most appropriate next step?
Select an answer first - 30
While analyzing a suspicious PE file, you notice that the section named .text has write permissions, and the import table includes VirtualAlloc and WriteProcessMemory. What is the most likely implication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.