
EC-CouncilDigital Forensics Essentials
Domain 7Objective 5
System and Network Behavior Analysis DFE Practice Questions (Page 8)
Part of the Malware Forensics domain, which makes up ~15% of our current practice bank.
38questions here
8free pages
3concepts
Questions 36–38
- 36
During a network behavior analysis, an analyst notices a workstation generating a large volume of DNS queries for random subdomains under a single domain, with each query receiving a response containing a different IP address. The workstation is also running an unusual process that is not present on other similar machines. What does this pattern most likely indicate?
Select an answer first - 37
A network analyst is examining traffic from a compromised host and sees that it is communicating with a server on port 53 using DNS queries that contain encoded data in the subdomain labels. The host also has a process that is injecting code into other processes. What is the most likely purpose of the DNS queries?
Select an answer first - 38
A security analyst is reviewing network captures from a compromised Linux server. The server is making periodic outbound connections to a remote IP on port 443, but the TLS handshake fails and the server immediately reconnects. The process making the connections is not listed in the server's process table. What is the most likely explanation for this behavior?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.