
EC-CouncilCertified Incident Handler
Domain 2Objective 2
Handling and Responding to Malware Incidents ECIH Practice Questions (Page 5)
Part of the First Response and Malware Incidents domain, which makes up ~22% of our current practice bank.
57questions here
12free pages
11concepts
Questions 21–25
- 21
A malware analyst is performing static analysis on a suspicious binary. Which activity is part of static analysis?
Select an answer first - 22
What is the primary goal of the recovery phase in malware incident response?
Select an answer first - 23
An organization discovers that a worm has been spreading across its network by exploiting a vulnerability in a network service. The worm is also dropping a backdoor on infected systems. Which containment strategy is MOST effective in stopping the worm's spread?
Select an answer first - 24
A company has suffered a malware outbreak that infected several servers and workstations. The malware is a polymorphic virus that has modified system files and created scheduled tasks. The incident response team has contained the infection and is now planning eradication. Which eradication approach is MOST effective given the polymorphic nature of the malware?
Select an answer first - 25
Which of the following lists the phases of malware incident response in the correct order?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.