
EC-CouncilDigital Forensics Essentials
Domain 7Objective 5
System and Network Behavior Analysis DFE Practice Questions (Page 1)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
38questions here
8free pages
3concepts
Questions 1–5
- 1
A network analyst is reviewing proxy logs and sees that a workstation has been making requests to a URL that contains a long string of hexadecimal characters, and the responses are also hexadecimal. The workstation is also running a process that is not in the company's approved software list. What is the most likely explanation for this traffic?
Select an answer first - 2
A forensic examiner is analyzing a Windows system and finds that the file C:\Windows\System32\drivers\etc\hosts has been modified to redirect several legitimate domains to 127.0.0.1. The examiner also finds a process named 'sysmon.exe' running from a non-standard location. What is the most likely purpose of the hosts file modification?
Select an answer first - 3
A network analyst observes a workstation making DNS queries for a domain that was only registered 24 hours ago. The workstation also maintains a persistent TCP connection to an IP address in a country where the company has no business operations. What should the analyst do next to confirm whether this is malicious C2 activity?
Select an answer first - 4
An incident responder is reconstructing the timeline of a malware infection. The responder has a packet capture showing an outbound connection to a known malicious IP at 02:15 UTC, and a file system image showing a suspicious executable created at 02:10 UTC on the same machine. What additional evidence would best confirm that the executable initiated the network connection?
Select an answer first - 5
An incident response team is investigating a ransomware infection. They have the following evidence: (1) a process named 'encrypt.exe' was created at 10:00 AM, (2) the process accessed a large number of files on the file system between 10:00 and 10:30 AM, (3) the process made an outbound connection to an external IP at 10:05 AM, and (4) the process terminated at 10:30 AM. The team needs to determine if the outbound connection was used to exfiltrate data before encryption. What is the most important evidence to review?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.