Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 7Objective 5

System and Network Behavior Analysis DFE Practice Questions (Page 7)

Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.

38questions here
8free pages
3concepts

Questions 31–35

  1. 31application · medium

    A network analyst is reviewing firewall logs and sees a workstation making periodic connections to a remote server on port 443 every 60 seconds, each transferring exactly 512 bytes. The workstation also has a process named 'winupdate.exe' running from a temp directory. What should the analyst conclude from this behavior?

    Select an answer first
  2. 32expert · hard

    An organization discovers that a server was compromised. The server's event logs show a successful login from an external IP at 2:00 AM. The server's file system shows that a new executable was created at 2:05 AM. Network logs show that the server made an outbound connection to an external IP at 2:10 AM. The organization wants to determine if the external IP that logged in is the same as the IP the server connected to. What is the best way to correlate this evidence?

    Select an answer first
  3. 33application · medium

    A forensic analyst is examining a Windows system and finds that a new DLL file was added to the system32 directory. The DLL is not signed and is not part of any known software. The analyst also finds that a process named 'explorer.exe' is loading this DLL. What is the most significant system behavior indicator that this DLL is malicious?

    Select an answer first
  4. 34application · medium

    A forensic analyst is examining a Windows system suspected of malware infection. The analyst finds a new registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run that points to a script in the user's Downloads folder. The script is scheduled to run at logon. What is the most significant system behavior indicator that this registry key is malicious?

    Select an answer first
  5. 35expert · hard

    An incident response team is investigating a breach. They have the following evidence: (1) a malicious executable was downloaded to a user's machine at 10:00 AM, (2) the executable created a service at 10:05 AM, (3) the service made an outbound connection to an external IP at 10:10 AM, and (4) the user's credentials were used to access an internal file share at 10:15 AM. The team needs to determine the scope of the breach. What is the most important question to answer?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.