CHFI Mobile and Malware Forensics • Set 2
CHFI Mobile and Malware Forensics Practice Test 2 — 15 questions with explanations. Free, no signup.
A malware analyst is examining a PE file that has a section named '.tls' and imports from 'kernel32.dll' and 'ntdll.dll'. The entry point points to a small stub that decrypts the main code at runtime. Which of the following best describes this technique?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.