Practice 212-89 Malware Incidents questions with full explanations on every answer.
Start practicing
Malware Incidents — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are using Wireshark to analyze traffic from an infected host. You notice consistent beaconing activity to an external IP on port 443. How do you isolate this traffic in your capture?
2You are analyzing a malware sample using Cuckoo Sandbox. The report shows the malware is attempting to modify the 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run' registry key. What is the intent of this activity?
3You are performing a live memory analysis using Volatility 3. You suspect a rootkit is hiding processes. Which plugin should you run to compare the process list from the EPROCESS block with the thread scheduler's list?
4A malware infection has encrypted several network shares. You decide to restore from backups. What is the most critical step to perform before restoring data to the production environment?
5You are using YARA to detect a specific strain of ransomware. You want to match a file if it contains a specific hex string OR a specific string value. How do you construct this in your rule?
6During an incident, you need to isolate a compromised workstation from the network immediately. Which action is the most effective containment strategy while preserving volatile memory?
7An analyst is reviewing logs from an EDR solution. They see a 'process hollowing' event. What is the primary purpose of this malware technique?
8During a malware incident response, you identify a suspicious process with PID 4452 using Sysinternals Process Explorer. You need to verify the file's reputation before isolation. Which action allows you to do this directly within the tool?
9You are analyzing a malware sample in a lab. You notice the malware uses the 'CreateRemoteThread' API. What is the objective of this malware activity?
10You are reviewing logs from an EDR and see an indicator of 'Living off the Land' (LotL). Which tool usage would be considered an LotL attack?
11You have identified an infected machine and need to perform a memory dump before it is wiped. Which tool is the industry standard for acquiring a full memory dump on a Windows machine for incident response?
12A user reports their system is running slowly, and you observe a suspicious file in 'C:\Users\[User]\AppData\Local\Temp'. What is the most appropriate first step in your investigation?
13After eradicating a malware infection, you need to ensure the system is hardened against future occurrences. Which action is most effective against fileless malware?
14An incident handler is analyzing a malware incident that used a phishing email. What is the most important field to check in the email header to determine the true origin of the email?
15You are analyzing a malware sample that uses Domain Generation Algorithms (DGA). What is the primary purpose of DGA in malware?
16A malware sample was found to use a 'Mutex' to ensure only one instance of the malware runs at a time. What tool would you use to find the Mutex name on an infected host?
17Which document is essential to maintain during a malware incident to ensure accountability and track the actions taken by the incident response team?
18You are performing forensic analysis on a suspicious file. You need to determine if it is a packed executable. Which tool is most effective for viewing the file's section headers to identify anomalies?
19You suspect a malware incident caused unauthorized data exfiltration. Which log source is most useful to identify the destination IP of the exfiltrated data?
20A system has been infected by a worm that is spreading across the network. What is the most immediate action to stop the spread?
21You are analyzing a malware sample that uses 'API Hooking'. What is the goal of this technique?
22You have identified a malicious DLL that is being loaded by a legitimate process. Which tool allows you to view which DLLs are loaded by a specific process?
23During the 'Recovery' phase of the malware incident, what must be done to ensure the environment is safe before reconnecting the restored systems?
24You suspect a file on a Linux server is malicious. What command can you use to obtain the MD5 hash of the file?
25During a malware analysis, which TWO of the following indicators are typically used to identify persistence mechanisms in the Windows registry?
26Which THREE of the following are considered 'behavioral' indicators of a malware infection?
27Which TWO of the following sources of information are most helpful for building an Indicators of Compromise (IoC) list during an investigation?
28Which THREE of the following tools would be most effective for performing live memory forensics on a compromised Windows workstation?
29When eradicating malware, which TWO of the following steps are essential to ensure the host is fully cleaned and the entry point is secured?
30Which THREE of the following are effective methods for protecting backup systems from being encrypted by ransomware?
31When analyzing a potentially malicious script, which THREE of the following techniques help in deobfuscating the code?
32Which TWO of the following activities are considered 'Eradication' steps in the incident response lifecycle?
33Which THREE of the following indicators are found in email-based malware delivery?
34When reviewing network traffic for C2 communication, which THREE of the following indicators are commonly observed?
The Malware Incidents domain covers the key concepts tested in this area of the 212-89 exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all 212-89 domains — no account required.
The Courseiva 212-89 question bank contains 34 questions in the Malware Incidents domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Malware Incidents domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included