
EC-CouncilEthical Hacking Essentials
Domain 2Objective 1
Malware Concepts, Types, and Attack Mechanisms EHE Practice Questions (Page 4)
Part of the Malware and Password Attacks domain, which makes up ~14% of our current practice bank.
43questions here
9free pages
6concepts
Questions 16–20
- 16
A security analyst is investigating a malware sample that changes its file hash every time it is downloaded from different command-and-control servers. The sample's code remains functionally identical, but the binary layout differs. Which obfuscation technique is the malware using, and why does it complicate hash-based detection?
Select an answer first - 17
A network administrator notices that a workstation is communicating with a known malicious IP address at regular intervals. The workstation also has a new service that was not installed by the administrator. Which indicator of compromise (IoC) is most directly related to the regular communication with the malicious IP?
Select an answer first - 18
In the malware lifecycle, which stage involves the malware ensuring it remains active across system reboots?
Select an answer first - 19
Which malware obfuscation technique involves encrypting the malicious code and decrypting it at runtime to evade signature-based detection?
Select an answer first - 20
A malware analyst is examining a suspicious binary. The binary's strings are not visible in a hex editor, and the file size is much smaller than expected. When executed in a sandbox, the binary unpacks itself in memory and runs. Which detection evasion technique is being used, and what is a reliable way to detect this malware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.