Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 7

Malware Forensics ECSS Practice Questions (Page 9)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

43questions here
9free pages
10concepts

Questions 41–43

  1. 41application · medium

    An analyst receives a suspicious executable from an incident. The file is packed with a custom packer, and the analyst suspects it may be a keylogger. The analyst must quickly determine whether the binary contains any embedded configuration strings without executing it. Which approach is most appropriate?

    Select an answer first
  2. 42application · medium

    A malware analyst is reverse engineering a packed binary. After unpacking, the analyst loads the binary into a debugger and sets a breakpoint on the Windows API function 'CreateProcess'. What is the primary purpose of this breakpoint?

    Select an answer first
  3. 43expert · hard

    An analyst is investigating a malware infection where the malware self-replicates across network shares and also installs a backdoor. The malware does not require user interaction to spread. How should this malware be classified?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to ECSS

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.