
EC-CouncilDigital Forensics Essentials
Domain 7Objective 5
System and Network Behavior Analysis DFE Practice Questions (Page 4)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
38questions here
8free pages
3concepts
Questions 16–20
- 16
An analyst finds a suspicious process on a host and also observes corresponding outbound connections from that host to an external IP. What is the primary value of correlating these two pieces of evidence?
Select an answer first - 17
A forensic analyst is analyzing a Windows system and finds that a process named 'lsass.exe' is running from C:\Windows\Temp\. The process is making outbound connections to an external IP. What is the most important system behavior to investigate?
Select an answer first - 18
A network analyst is reviewing proxy logs and finds that a workstation is making frequent requests to a domain that is known to be a malware distribution site. The requests are all for the same URL and occur every 5 minutes. The workstation's user says they have not visited that site. What is the most likely explanation?
Select an answer first - 19
A security analyst is reviewing network traffic and notices a host sending large amounts of data to an external IP address using the FTP protocol on port 21. The host is a database server that normally does not use FTP. The analyst also sees that a new service named 'FTPHelper' was installed on the host. What is the most likely explanation?
Select an answer first - 20
A security analyst is examining a compromised Linux server. The analyst finds a new user account with UID 0, a modified /etc/ld.so.preload file, and a cron job that downloads a script from an external IP. Which system behavior indicators should be reported as the most critical for confirming rootkit activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.