
EC-CouncilDigital Forensics Essentials
Domain 7Objective 3
Static Malware Analysis DFE Practice Questions (Page 7)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
9concepts
Questions 31–35
- 31
An analyst is analyzing a malware sample that uses dynamic API resolution. The import table only contains LoadLibrary and GetProcAddress. The analyst needs to identify the specific APIs the malware calls. Which approach is most effective?
Select an answer first - 32
What does it indicate if a tool like PEiD or Detect It Easy reports that an executable is 'packed'?
Select an answer first - 33
A malware analyst extracts the resources from a suspicious executable and finds a large binary blob in the 'RCData' section, along with a custom icon. The strings inside the blob include 'MZ' and 'This program cannot be run in DOS mode'. What is the most likely conclusion?
Select an answer first - 34
During static analysis of a Windows executable, an analyst examines the PE header and notices that the SizeOfOptionalHeader field is larger than the standard value for a PE32+ file. What should the analyst infer?
Select an answer first - 35
A malware analyst has a sample that is detected by only one antivirus engine as 'Trojan.Generic'. The analyst needs to determine if the file is truly malicious. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.