
EC-CouncilCertified Security Specialist
Domain 6Objective 7
Malware Forensics ECSS Practice Questions (Page 9)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
43questions here
9free pages
10concepts
Questions 41–43
- 41
An analyst receives a suspicious executable from an incident. The file is packed with a custom packer, and the analyst suspects it may be a keylogger. The analyst must quickly determine whether the binary contains any embedded configuration strings without executing it. Which approach is most appropriate?
Select an answer first - 42
A malware analyst is reverse engineering a packed binary. After unpacking, the analyst loads the binary into a debugger and sets a breakpoint on the Windows API function 'CreateProcess'. What is the primary purpose of this breakpoint?
Select an answer first - 43
An analyst is investigating a malware infection where the malware self-replicates across network shares and also installs a backdoor. The malware does not require user interaction to spread. How should this malware be classified?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECSS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.