Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 2Objective 2

Malware Propagation Techniques and Indicators EHE Practice Questions (Page 4)

Part of the Malware and Password Attacks domain, which makes up ~14% of our current practice bank.

31questions here
7free pages
5concepts

Questions 16–20

  1. 16application · easy

    A forensic analyst is examining a compromised Windows workstation. The analyst finds a new service named 'Windows Update Helper' that is set to auto-start, and the user reports that the system occasionally freezes. Which combination of indicators is the analyst documenting?

    Select an answer first
  2. 17application · medium

    A network administrator is reviewing proxy logs and sees that a workstation is making periodic HTTPS requests to a domain that was registered only a few days ago. The requests occur every 60 seconds, and the responses are unusually large for the small request size. The workstation's user reports no unusual behavior. Which indicator is the administrator observing?

    Select an answer first
  3. 18application · medium

    A system administrator notices that a server has a new scheduled task that runs a PowerShell script every hour. The script downloads a file from an external URL and executes it. The administrator also sees that the server's hosts file has been modified to redirect a known security vendor's domain to 127.0.0.1. Which propagation technique and indicator are present?

    Select an answer first
  4. 19application · medium

    A security analyst is reviewing firewall logs and notices that a single internal host is making outbound connections to multiple IP addresses on port 445, and some of those connections are being established successfully. The analyst also sees that the host recently downloaded a file from a file-sharing website. Which propagation technique is the analyst most likely observing?

    Select an answer first
  5. 20expert · medium

    A security analyst is investigating a server that is exhibiting multiple signs of compromise: a new user account was created, a scheduled task runs an unknown binary, and the server is making outbound connections to a known malicious IP. The analyst also notes that the server's performance has degraded. Which combination of indicators is the analyst documenting?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.