Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 3

Static Malware Analysis DFE Practice Questions (Page 8)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

51questions here
11free pages
9concepts

Questions 36–40

  1. 36expert · hard

    A forensic analyst is examining a suspicious executable and finds that it imports CreateRemoteThread, OpenProcess, and VirtualAllocEx. The analyst also extracts strings that include a path to a legitimate system DLL. What is the most likely functionality of the malware?

    Select an answer first
  2. 37application · medium

    An analyst uses Detect It Easy (DIE) on a suspicious executable and the tool reports 'UPX (Ultimate Packer for Executables)'. What is the most appropriate next step?

    Select an answer first
  3. 38foundation · easy

    What is the primary purpose of computing a hash (e.g., MD5, SHA-1, SHA-256) of a malware sample?

    Select an answer first
  4. 39foundation · easy

    What can an analyst infer if a malware sample imports the function 'InternetOpenUrlA' from wininet.dll?

    Select an answer first
  5. 40expert · hard

    A malware analyst is examining a suspicious executable that is packed with a custom packer. The analyst attempts to unpack it manually but is unable to do so. The import table shows only LoadLibraryA and GetProcAddress. The analyst has limited time and must decide whether to continue static analysis or switch to dynamic analysis. What is the most appropriate decision?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.