You must analyze live response output and memory dumps to identify malware type, persistence, and infection vector, then recommend containment. The single most important thing is correlating process, network, and autorun artifacts to confirm malicious activity rather than guessing from symptoms alone.
Start practicing
Malware Forensics — choose a session length
Free · No account required
Domain overview
Malware Forensics covers identifying, containing, and analyzing malicious code on Windows systems using forensic tooling. Questions present exhibits of command output, memory dumps, or infected workstations and ask you to conclude the malware type, persistence mechanism, or next investigative step. Expect scenarios on ransomware, trojans, and pop-up/adware infections with artifacts from live response and memory analysis.
Exam objectives
Interpreting netstat, tasklist, and autoruns output to spot malicious processes and persistence
Using Volatility plugins like pslist, netscan, and malfind on acquired memory dumps
Identifying ransomware indicators such as encrypted file extensions and ransom notes
Tracing initial infection vectors from email attachments and downloaded installers
Assuming a slow system with high network use is malware without correlating process, connection, and autorun artifacts
Confusing legitimate Windows processes with malware solely by name instead of checking path, hash, and parent process
Relying only on disk artifacts and ignoring volatile memory evidence that reveals injected code and active connections
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization suspects a stealthy malware infection on a critical server. Traditional antivirus and EDR solutions have not detected anything. Which forensic approach would be most effective in identifying the malware, given that it likely resides only in memory?
2During malware analysis, an investigator finds that a suspicious process is injecting code into a legitimate system process (e.g., explorer.exe). Which technique is being used?
3Refer to the exhibit. An investigator is examining a disk image using TSK. The output from 'fls' shows the directory structure. What is the significance of the entry 'V/V 113-128-1: $OrphanFiles'?
4You are a forensic analyst investigating a suspected malware infection on a Windows 10 workstation. The user reports that the system has been slow and that unexpected pop-ups appear. You have acquired a memory dump and a disk image. During analysis, you find a suspicious process named 'svch0st.exe' running with PID 4567. The process has loaded several DLLs, including 'wininet.dll' and 'ws2_32.dll'. You also find that the process has an active TCP connection to an external IP address 203.0.113.5 on port 4444. In the disk image, you find an executable file at C:\Users\Public\svch0st.exe with a creation date that matches the start of symptoms. The file's hash is not in any known malware database. You decide to perform dynamic analysis by running the file in a sandbox. However, the sandbox environment has no network connectivity. The executable runs but does not exhibit any malicious behavior. What should you do next to determine if the file is malicious?
5Based on the exhibit, what is the most likely indication of malware persistence?
6You are investigating a Windows 10 workstation that exhibits slow performance and frequent pop-ups. The user reports that the system started acting strangely after installing a 'PDF Converter' from an email attachment. You suspect malware. You have captured a memory dump using FTK Imager and a network capture during the infection. In the memory dump, you find a suspicious process 'conhost.exe' running from a non-standard location (C:\Users\Public\Temp). The process has an open handle to a file named 'config.ini' in the same directory. The network capture shows periodic HTTPS connections to 'malicious.com' on port 443 from the workstation's IP. Using Volatility, you extract the process's command line: 'conhost.exe -hidden -log C:\Users\Public\Temp\output.log'. Which of the following is the BEST immediate course of action to contain the threat and preserve evidence?
7Refer to the exhibit. During a malware investigation, a forensic analyst runs the commands shown. What is the most likely conclusion?
8You are a forensic analyst investigating a Windows workstation that shows signs of malware infection. The user reports that the system is slow, network activity is high, and several files have been encrypted with a .encrypted extension. A ransom note named README.txt has been left on the desktop demanding payment. You have acquired a memory dump using FTK Imager and a disk image using dd. You need to identify the malware family and gather indicators of compromise (IOCs). Which of the following is the MOST appropriate first step?
9A forensic examiner is analyzing a potentially malicious Portable Executable (PE) file recovered from a compromised host. The examiner uses PEStudio to inspect the file and notices that the Import Address Table (IAT) contains only two functions: LoadLibraryA and GetProcAddress. Which of the following does this most likely indicate?
10A forensic analyst is investigating a malware incident on a Windows system and suspects that the malware uses process injection to execute malicious code within a legitimate process. The analyst has acquired a memory dump of the system. Which two of the following techniques should the analyst use to detect and analyze process injection? (Choose two.)
11A forensic investigator is examining a suspicious file and wants to determine its true file type regardless of its extension. The investigator runs the 'file' command on the file and receives the output 'PE32 executable (GUI) Intel 80386, for MS Windows'. However, the file has a .txt extension. What is the most likely explanation for this discrepancy?
You must analyze live response output and memory dumps to identify malware type, persistence, and infection vector, then recommend containment. The single most important thing is correlating process, network, and autorun artifacts to confirm malicious activity rather than guessing from symptoms alone.
The Courseiva CHFI question bank contains 11 questions in the Malware Forensics domain, covering the 7% of the exam attributed to this domain in the official EC-Council blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Malware Forensics domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included