
EC-CouncilDigital Forensics Essentials
Domain 7Objective 5
System and Network Behavior Analysis DFE Practice Questions (Page 2)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
38questions here
8free pages
3concepts
Questions 6–10
- 6
A forensic analyst is investigating a Windows system and finds that a scheduled task was created that runs a PowerShell script every hour. The script is located in the user's AppData\Roaming folder. The analyst also finds that the script makes an HTTP request to an external URL. What is the most significant indicator that this scheduled task is malicious?
Select an answer first - 7
A security analyst is reviewing network traffic and notices that a server is making outbound connections to an IP address on port 445 (SMB) that is not part of the internal network. The server is a web server and should not be making SMB connections. What is the most likely explanation?
Select an answer first - 8
An incident responder is reconstructing the timeline of a malware infection. The responder has the following evidence: (1) a network log showing a connection to a known malicious IP at 12:00:00, (2) a file system image showing a file named 'malware.exe' created at 11:59:55, (3) a process log showing 'malware.exe' running from 11:59:58 to 12:05:00, and (4) a registry log showing a Run key added at 12:01:00 pointing to 'malware.exe'. What is the most likely sequence of events?
Select an answer first - 9
A forensic examiner is analyzing a Windows system that is suspected of being infected with a rootkit. The examiner finds that the process list does not show a known malicious process, but network traffic shows connections to a known C2 server. The examiner also finds that the registry key HKLM\SYSTEM\CurrentControlSet\Services has a new service named 'LegitService' that points to a file in the Temp folder. What is the most likely explanation for the hidden process?
Select an answer first - 10
Which network behavior is a common indicator of malware command-and-control activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.