Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 5

System and Network Behavior Analysis DFE Practice Questions (Page 1)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

38questions here
8free pages
3concepts

Questions 1–5

  1. 1application · medium

    A network analyst is reviewing proxy logs and sees that a workstation has been making requests to a URL that contains a long string of hexadecimal characters, and the responses are also hexadecimal. The workstation is also running a process that is not in the company's approved software list. What is the most likely explanation for this traffic?

    Select an answer first
  2. 2application · medium

    A forensic examiner is analyzing a Windows system and finds that the file C:\Windows\System32\drivers\etc\hosts has been modified to redirect several legitimate domains to 127.0.0.1. The examiner also finds a process named 'sysmon.exe' running from a non-standard location. What is the most likely purpose of the hosts file modification?

    Select an answer first
  3. 3application · medium

    A network analyst observes a workstation making DNS queries for a domain that was only registered 24 hours ago. The workstation also maintains a persistent TCP connection to an IP address in a country where the company has no business operations. What should the analyst do next to confirm whether this is malicious C2 activity?

    Select an answer first
  4. 4application · medium

    An incident responder is reconstructing the timeline of a malware infection. The responder has a packet capture showing an outbound connection to a known malicious IP at 02:15 UTC, and a file system image showing a suspicious executable created at 02:10 UTC on the same machine. What additional evidence would best confirm that the executable initiated the network connection?

    Select an answer first
  5. 5expert · hard

    An incident response team is investigating a ransomware infection. They have the following evidence: (1) a process named 'encrypt.exe' was created at 10:00 AM, (2) the process accessed a large number of files on the file system between 10:00 and 10:30 AM, (3) the process made an outbound connection to an external IP at 10:05 AM, and (4) the process terminated at 10:30 AM. The team needs to determine if the outbound connection was used to exfiltrate data before encryption. What is the most important evidence to review?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.