
EC-CouncilDigital Forensics Essentials
Domain 7Objective 3
Static Malware Analysis DFE Practice Questions (Page 9)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
51questions here
11free pages
9concepts
Questions 41–45
- 41
A security analyst receives a suspicious executable from a user. Before submitting it to an online multi-engine scanner, the analyst wants to ensure the sample is not altered during transit and to allow correlation with other teams. Which action best achieves this?
Select an answer first - 42
An analyst is reviewing the import table of a suspicious executable. The imports include CreateFile, WriteFile, InternetOpen, InternetConnect, and HttpSendRequest. What is the most reasonable inference about the malware's capabilities?
Select an answer first - 43
Why do analysts often use multiple antivirus engines to scan a malware sample?
Select an answer first - 44
What does a detection result from an antivirus engine indicate?
Select an answer first - 45
A security team is analyzing a suspicious executable. Static analysis reveals that the file is packed, and antivirus detection is low (2/60). The team has a limited budget and must decide whether to invest in manual unpacking and deep static analysis or to run the sample in a sandbox for dynamic analysis. What is the most appropriate decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.