Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 5

System and Network Behavior Analysis DFE Practice Questions (Page 5)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

38questions here
8free pages
3concepts

Questions 21–25

  1. 21expert · hard

    An incident response team is investigating a malware infection. They have the following evidence: (1) a malicious file was created on the file system at 10:00 AM, (2) a process named 'update.exe' started at 10:02 AM, (3) the process made an outbound connection to an external IP at 10:05 AM, and (4) the process was terminated at 10:10 AM. The team needs to determine if the outbound connection was used to exfiltrate data. What is the most important evidence to review?

    Select an answer first
  2. 22foundation · easy

    Which of the following is a system-level indicator of compromise that an analyst would look for during malware forensics?

    Select an answer first
  3. 23foundation · easy

    An analyst reviews network traffic and notices a workstation sending small, periodic HTTPS requests to a domain that has no historical presence in the organization. This pattern is most indicative of which type of activity?

    Select an answer first
  4. 24foundation · easy

    Why is it important to correlate system logs with network logs during a malware investigation?

    Select an answer first
  5. 25application · medium

    A forensic analyst is investigating a Windows workstation that is suspected of malware infection. The analyst observes a process named 'svchost.exe' running from C:\Users\Public\Temp and making repeated HTTPS connections to a domain that was registered three days ago. Which two system and network artifacts should the analyst prioritize for correlation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.