
EC-CouncilCertified Security Specialist
Domain 6Objective 7
Malware Forensics ECSS Practice Questions (Page 4)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
43questions here
9free pages
10concepts
Questions 16–20
- 16
An incident responder has completed static and dynamic analysis of a worm that spreads via USB drives. The responder must now produce a forensic report that will be used in legal proceedings. Which section is most critical to include to ensure the report is admissible and useful?
Select an answer first - 17
Which type of malware is designed to encrypt a victim's files and demand payment for the decryption key?
Select an answer first - 18
An analyst is performing static analysis on a suspicious binary. The binary has a high entropy score and a very small import table. What does this combination most likely indicate?
Select an answer first - 19
An analyst receives a suspicious executable from a compromised workstation. The file is flagged by antivirus as a trojan, but the analyst needs to confirm the indicator before submitting it to the sandbox. The analyst hashes the file, extracts printable strings, and examines the PE header. Which conclusion can the analyst draw from these static steps alone?
Select an answer first - 20
A digital forensics investigator is called to analyze a machine infected with a worm. The investigator needs to produce a report that explains how the worm spreads and what indicators of compromise (IOCs) were found. Which approach best aligns with the role of malware forensics in this investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.