
EC-CouncilDigital Forensics Essentials
Domain 7Objective 5
System and Network Behavior Analysis DFE Practice Questions (Page 6)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
38questions here
8free pages
3concepts
Questions 26–30
- 26
An incident responder is investigating a ransomware attack. The responder has a network log showing a connection to a file-sharing site at 03:00 UTC, and a file system image showing that many documents were encrypted at 03:05 UTC. The responder also finds a process named 'encryptor.exe' that was created at 02:55 UTC. What is the most likely sequence of events?
Select an answer first - 27
An incident responder is analyzing a malware infection on a server. The responder has a network capture showing a connection to a known malicious IP address on port 443 at 10:00:00, and a file system image showing a new file created at 09:59:55 named 'svc.exe'. The responder also finds a new service registered in the registry at 09:59:58 that points to svc.exe. What is the most likely sequence of events?
Select an answer first - 28
A network analyst is reviewing firewall logs and notices that a workstation is making outbound connections to a remote IP on port 53 (DNS) at regular intervals. The connections are not DNS queries; they are raw TCP connections to port 53. What is the most likely explanation?
Select an answer first - 29
A forensic team is investigating a suspected data breach. They have the following evidence: (1) a network log showing a large outbound transfer to an external IP at 02:00 UTC, (2) a file system image showing a compressed archive created at 01:55 UTC containing sensitive files, and (3) a process log showing a process named 'backup.exe' running from 01:50 to 02:05 UTC. The team also finds that the external IP is a known file-sharing service. Which conclusion is best supported by the evidence?
Select an answer first - 30
A forensic analyst is examining a Windows system and finds that the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run has a new value named 'Updater' pointing to C:\Users\Public\update.exe. The analyst also finds that the file update.exe is a known malware sample. What is the most likely reason for this registry entry?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.