Practice 312-39 Forensic Investigation And Malware Analysis questions with full explanations on every answer.
Start practicing
Forensic Investigation And Malware Analysis — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
While investigating a potential malware infection, a SOC analyst needs to determine if a specific binary has been analyzed by the security community before. Which platform is the industry standard for checking the reputation of a file hash across dozens of antivirus engines?
2You have captured a malicious binary and are performing dynamic analysis. You observe the malware attempting to resolve a domain that you want to intercept. Which tool allows you to simulate a DNS server response to redirect the malware traffic to a local analysis machine?
3During an incident response, you identify a persistent malware process. You need to see exactly which files and registry keys the process is touching in real-time. Which Sysinternals tool provides this capability?
4A SOC analyst is analyzing a suspicious email attachment. The analyst wants to extract URLs and embedded files without detonating the payload in a full sandbox. Which tool is recommended for this type of file parsing?
5You are performing static analysis on an suspicious executable. You want to view the imported functions, strings, and headers without executing the code. Which tool is most appropriate for this task?
6You are examining a suspicious file and suspect it is packed (obfuscated). Which technique or tool helps identify if a file is likely packed?
7When conducting a forensic investigation, you need to ensure the integrity of the collected digital evidence. What is the most critical step to perform immediately after copying the original media to a forensic workstation?
8When analyzing network traffic associated with a malware C2 channel, you observe encrypted traffic. Which approach allows you to inspect the content of this traffic without the malware's private key?
9When performing static analysis of a malicious binary, which THREE indicators should an analyst typically look for?
10You are investigating a file-less malware infection. Where in the Windows Registry would you look to identify common persistence mechanisms used by malicious scripts?
11Which TWO types of evidence are classified as 'volatile' and should be captured first during a forensic investigation?
12A SOC analyst is preparing to collect digital evidence from a compromised server. Which TWO actions must be documented to maintain a proper Chain of Custody?
13An analyst is investigating a compromised system. Which THREE of the following artifacts are commonly checked for indicators of persistence?
14A SOC analyst is analyzing a suspected PowerShell-based attack. Which Windows log event ID is primarily used to log executed PowerShell command blocks?
15In the context of malware analysis, which TWO of the following are primary differences between static and dynamic analysis?
The Forensic Investigation And Malware Analysis domain covers the key concepts tested in this area of the 312-39 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 312-39 domains — no account required.
The Courseiva 312-39 question bank contains 15 questions in the Forensic Investigation And Malware Analysis domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Forensic Investigation And Malware Analysis domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included