Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 5

System and Network Behavior Analysis DFE Practice Questions (Page 6)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

38questions here
8free pages
3concepts

Questions 26–30

  1. 26application · medium

    An incident responder is investigating a ransomware attack. The responder has a network log showing a connection to a file-sharing site at 03:00 UTC, and a file system image showing that many documents were encrypted at 03:05 UTC. The responder also finds a process named 'encryptor.exe' that was created at 02:55 UTC. What is the most likely sequence of events?

    Select an answer first
  2. 27application · medium

    An incident responder is analyzing a malware infection on a server. The responder has a network capture showing a connection to a known malicious IP address on port 443 at 10:00:00, and a file system image showing a new file created at 09:59:55 named 'svc.exe'. The responder also finds a new service registered in the registry at 09:59:58 that points to svc.exe. What is the most likely sequence of events?

    Select an answer first
  3. 28application · medium

    A network analyst is reviewing firewall logs and notices that a workstation is making outbound connections to a remote IP on port 53 (DNS) at regular intervals. The connections are not DNS queries; they are raw TCP connections to port 53. What is the most likely explanation?

    Select an answer first
  4. 29expert · hard

    A forensic team is investigating a suspected data breach. They have the following evidence: (1) a network log showing a large outbound transfer to an external IP at 02:00 UTC, (2) a file system image showing a compressed archive created at 01:55 UTC containing sensitive files, and (3) a process log showing a process named 'backup.exe' running from 01:50 to 02:05 UTC. The team also finds that the external IP is a known file-sharing service. Which conclusion is best supported by the evidence?

    Select an answer first
  5. 30application · medium

    A forensic analyst is examining a Windows system and finds that the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run has a new value named 'Updater' pointing to C:\Users\Public\update.exe. The analyst also finds that the file update.exe is a known malware sample. What is the most likely reason for this registry entry?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.