
EC-CouncilDigital Forensics Essentials
Domain 7Objective 5
System and Network Behavior Analysis DFE Practice Questions (Page 3)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
38questions here
8free pages
3concepts
Questions 11–15
- 11
During an investigation, an analyst finds that a malware sample creates a file named 'payload.dll' in the Windows Temp folder and then modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run to point to that file. The analyst also observes outbound connections to an IP address on port 445. What is the most likely purpose of the registry modification?
Select an answer first - 12
An incident responder is analyzing a host that is suspected of communicating with a C2 server. The responder has the following observations: (1) the host makes a DNS query for 'update.example.com' every 5 minutes, (2) the host also makes an HTTPS connection to 'update.example.com' immediately after each DNS query, (3) the host has a process named 'svchost.exe' running from a temp directory. The responder needs to determine if the host is compromised. Which additional evidence would be most useful to confirm the C2 communication?
Select an answer first - 13
A forensic analyst is investigating a server that is suspected of being part of a botnet. The analyst finds the following: (1) a process named 'system.exe' running from C:\Windows\Temp, (2) the process is making many outbound connections to different IP addresses on port 80, (3) the process has a low CPU usage but high network activity. The analyst also finds that the server's hosts file has been modified to block access to security vendor websites. What is the most likely purpose of the hosts file modification?
Select an answer first - 14
A forensic analyst is examining a Windows system and finds that a new service was created that runs an executable from C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\update.exe. The service is set to start automatically. The analyst also finds that the executable makes outbound connections to an external IP. What is the most significant system behavior indicator that this service is malicious?
Select an answer first - 15
During a malware investigation, an analyst observes a process that repeatedly creates and deletes files in the Windows Temp directory and modifies the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key. Which type of indicator is the registry modification primarily considered?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.