
EC-CouncilCertified Security Specialist
Domain 6Objective 7
Malware Forensics ECSS Practice Questions (Page 2)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
43questions here
9free pages
10concepts
Questions 6–10
- 6
A malware analyst is examining a binary that appears to have a low entropy section and a small number of imported functions. The binary also contains a section named '.UPX0' and '.UPX1'. The analyst suspects the binary is packed. Which static analysis technique would best confirm this and help unpack the binary?
Select an answer first - 7
After completing dynamic analysis of a trojan, an analyst must write a forensic report for legal proceedings. Which element is most important to include to ensure the report is defensible in court?
Select an answer first - 8
A malware analyst is reverse engineering a trojan that uses a custom obfuscation technique to hide its control flow. The analyst has identified that the trojan uses a state machine to decide which payload to execute based on the system's locale. The analyst needs to understand the logic and determine which payload is executed for a specific locale. Which approach is most effective?
Select an answer first - 9
Which of the following is a typical observation made during dynamic malware analysis?
Select an answer first - 10
A malware analyst is reverse engineering a trojan that uses anti-debugging techniques. The analyst needs to understand the control flow of the main function and bypass the anti-debugging checks to reach the payload. Which tool and technique combination is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.