
EC-CouncilDigital Forensics Essentials
Domain 7Objective 5
System and Network Behavior Analysis DFE Practice Questions (Page 5)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
38questions here
8free pages
3concepts
Questions 21–25
- 21
An incident response team is investigating a malware infection. They have the following evidence: (1) a malicious file was created on the file system at 10:00 AM, (2) a process named 'update.exe' started at 10:02 AM, (3) the process made an outbound connection to an external IP at 10:05 AM, and (4) the process was terminated at 10:10 AM. The team needs to determine if the outbound connection was used to exfiltrate data. What is the most important evidence to review?
Select an answer first - 22
Which of the following is a system-level indicator of compromise that an analyst would look for during malware forensics?
Select an answer first - 23
An analyst reviews network traffic and notices a workstation sending small, periodic HTTPS requests to a domain that has no historical presence in the organization. This pattern is most indicative of which type of activity?
Select an answer first - 24
Why is it important to correlate system logs with network logs during a malware investigation?
Select an answer first - 25
A forensic analyst is investigating a Windows workstation that is suspected of malware infection. The analyst observes a process named 'svchost.exe' running from C:\Users\Public\Temp and making repeated HTTPS connections to a domain that was registered three days ago. Which two system and network artifacts should the analyst prioritize for correlation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.