Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 7

Malware Forensics ECSS Practice Questions (Page 3)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

43questions here
9free pages
10concepts

Questions 11–15

  1. 11foundation · easy

    What is a key requirement for a malware analysis environment?

    Select an answer first
  2. 12application · medium

    An analyst is setting up a malware analysis lab. The lab uses a VM with a snapshot taken before each analysis. The VM is connected to a virtual network that blocks outbound traffic except to a simulated C2 server. Why is this network configuration important for dynamic analysis?

    Select an answer first
  3. 13expert · hard

    An analyst is writing a forensic report on a ransomware infection. The report must be suitable for both legal proceedings and incident response. The analyst has documented the file hashes, C2 domains, and persistence mechanisms. Which additional element is most important to include for legal proceedings?

    Select an answer first
  4. 14application · easy

    During dynamic analysis of a ransomware sample, the analyst observes that the malware creates a scheduled task that runs a PowerShell script at system startup. Which persistence mechanism is the malware using?

    Select an answer first
  5. 15expert · hard

    An analyst is setting up a malware analysis lab for a team that will analyze both Windows and Linux malware. The lab has limited hardware and must support multiple concurrent analyses. Which setup is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.