Courseiva

CEH · topic practice

Cryptography and Malware Analysis practice questions

This CEH domain covers cryptographic algorithms, PKI, encryption tools, and malware analysis techniques including static and dynamic analysis, sandbox evasion, and forensic detection. Questions present practical scenarios requiring you to select the correct key exchange, cipher mode, hashing method, or malware analysis tool and interpret observed artifacts accurately.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cryptography and Malware Analysis

What the exam tests

What to know about Cryptography and Malware Analysis

Match cryptographic primitives to their properties: PFS requires ephemeral Diffie-Hellman variants, not static RSA. For malware, correlate key length and ciphertext size to infer the algorithm. For keyloggers, distinguish hardware from software and choose physical or USB-level detection accordingly.

Selecting ECDHE or DHE key exchange to enable Perfect Forward Secrecy in TLS

Identifying symmetric ciphers like AES, DES, and 3DES by key length and block size

Using sandbox evasion indicators such as CPU core count and VM artifacts

Detecting hardware keyloggers through physical inspection and USB device auditing

Watch out for

Common Cryptography and Malware Analysis exam traps

  • ▸Confusing RSA key exchange with PFS-capable ECDHE/DHE, since static RSA does not provide forward secrecy
  • ▸Assuming any 16-byte hardcoded key implies AES-128 without verifying block cipher mode or algorithm
  • ▸Treating software keylogger detection tools as effective against hardware keyloggers that sit inline with the keyboard

Practice set

Cryptography and Malware Analysis questions

20 questions · select your answer, then reveal the explanation

Which THREE of the following are types of cryptanalytic attacks? (Choose three.)

A malware analyst is investigating a suspicious executable that appears to be a Trojan. The analyst runs the executable in a sandbox and observes the following behavior: it creates a hidden file in the %AppData% directory, modifies the Windows registry to add a startup entry, and attempts to connect to an external IP address on port 443 using HTTPS. Which TWO of the following techniques are likely being used by this malware?

Refer to the exhibit. A security analyst runs netstat on a compromised Windows machine. Based on the output, which process is most likely associated with the malicious activity?

Exhibit

Refer to the exhibit.

C:\Users\Admin>netstat -anob

Active Connections

  Proto  Local Address          Foreign Address        State           PID
  TCP    192.168.1.10:49152     203.0.113.5:4444       ESTABLISHED     1234
  TCP    192.168.1.10:49153     198.51.100.20:80       TIME_WAIT       5678
  [svchost.exe]
  TCP    192.168.1.10:49154     203.0.113.5:4444       ESTABLISHED     1234
  [explorer.exe]
Question 4mediumdrag order
Read the full wireless explanation →

Drag and drop the steps to configure a wireless network with WPA2-Enterprise authentication on a Cisco AP into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

A security analyst is examining a suspicious executable recovered from a compromised workstation. Static analysis reveals that the file is packed with a commercial packer. The analyst wants to observe the malware's runtime behavior and extract the original unpacked code from memory without allowing the malware to communicate with its command-and-control (C2) server. Which approach is most appropriate?

A security analyst receives an alert about a suspicious file hash. The analyst wants to check if the file is known malware by querying an online database of malware signatures. Which tool should the analyst use?

During a penetration test, an ethical hacker finds that a web application transmits sensitive data in plaintext over HTTPS. Which of the following best describes this security issue?

A company's internal PKI uses an offline root CA and an online issuing CA. A security engineer needs to revoke a compromised certificate issued by the online CA. Which CRL distribution point should the engineer update?

A security analyst suspects that a user's machine is infected with a keylogger. Which of the following is the most effective method to detect a hardware keylogger?

An ethical hacker is analyzing a piece of malware that uses a custom encryption algorithm. The malware sample contains a hardcoded key that is 16 bytes long. The analyst observes that the encrypted data is the same length as the plaintext. Which encryption mode is most likely being used?

During a forensic investigation, an analyst finds that a malware sample uses a technique to detect if it is running in a sandbox by checking the number of CPU cores. The malware terminates execution if the core count is less than 2. Which anti-analysis technique is this?

A company wants to secure its email communications using digital signatures. Which cryptographic key does the sender use to sign the email?

Which TWO of the following are characteristics of a polymorphic virus? (Choose two.)

You are a security analyst for a medium-sized company. The company uses a custom web application for internal project management. The application uses AES-256-CBC for encrypting sensitive data stored in the database. Recently, the company experienced a data breach where an attacker exfiltrated the entire database. Although the data was encrypted, the attacker was able to decrypt some records. Investigation reveals that the encryption key is stored in a configuration file on the same server, and the initialization vector (IV) is hardcoded in the application code. Additionally, the application uses the same key for all records. Which of the following is the most effective remediation to prevent future decryption of stolen encrypted data?

Refer to the exhibit. An analyst suspects that the downloaded file 'update.exe' may have been tampered with. The vendor's official website lists the SHA256 hash as 4e7c2a8f9b3d1e5f6a0c8b7d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f. What should the analyst conclude?

Exhibit

Refer to the exhibit.

---
C:\> certutil -hashfile C:\Users\Admin\Downloads\update.exe SHA256
SHA256 hash of C:\Users\Admin\Downloads\update.exe:
4e7c2a8f9b3d1e5f6a0c8b7d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f
---

During a penetration test, a security analyst discovers that an organization's web application uses HTTP for login forms, potentially exposing credentials to interception. Which of the following is the BEST cryptographic control to implement to protect credentials in transit?

A security engineer needs to configure a web server to support Perfect Forward Secrecy (PFS) for HTTPS connections. Which of the following key exchange methods should be prioritized?

You are a security analyst at a financial institution. The SOC has detected anomalous outbound traffic from a server in the DMZ to an unknown IP address on TCP port 8443. The server runs a custom application that normally communicates with internal databases on port 1433. The server's OS is Windows Server 2019. Preliminary analysis shows that a new service named 'UpdateSvc' was installed three days ago, set to start automatically, and runs under the LocalSystem account. The service binary is located at C:\Windows\System32\svchost.exe (the legitimate one). However, the service's 'ImagePath' registry key points to 'C:\Windows\System32\svchost.exe -k UpdateSvc'. Additionally, a scheduled task named 'HealthCheck' runs every hour and executes 'powershell.exe -EncodedCommand <base64>'. The encoded command decodes to a script that downloads a payload from the same unknown IP on port 8443 and executes it in memory. The server has antivirus installed that detected nothing. As the analyst, which of the following is the BEST immediate course of action?

An organization is investigating a potential malware infection. The security analyst observes unusual outbound connections to a known malicious IP address and finds a suspicious process running under a user's session. The analyst decides to perform memory analysis using Volatility. Which TWO commands would be most useful to identify the malicious process and its network connections?

You are a security analyst for a financial institution. The company has deployed a network of 500 Windows 10 workstations and 50 servers running Windows Server 2019. All systems are protected by a next-generation firewall and an endpoint detection and response (EDR) solution. Recently, several employees reported that their workstations are running slowly and exhibiting unusual pop-up messages demanding a ransom note in Bitcoin. The EDR alerts show that a file named 'invoice.docm' was downloaded from an email attachment and executed on multiple workstations. The EDR also indicates that the file dropped a PowerShell script that connected to an external IP address and downloaded additional payloads. After the initial infection, the EDR detected that the ransomware binary 'encryptor.exe' was executed, which began encrypting files. However, the encryption process was stopped by the EDR before all files were encrypted. The incident response team needs to determine the source of the infection and prevent future occurrences. Which of the following is the most effective first step to identify the initial infection vector?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cryptography and Malware Analysis sessions

Start a Cryptography and Malware Analysis only practice session

Every question in these sessions is drawn from the Cryptography and Malware Analysis domain — nothing else.

Related practice questions

Related CEH topic practice pages

Move into related areas when this topic feels solid.

Scanning Networks and Enumeration practice questions

Scanning Networks and Enumeration practice questions for CEH.

Wireless, IoT and Cloud Security practice questions

Wireless, IoT and Cloud Security practice questions for CEH.

Vulnerability Analysis and System Hacking practice questions

Practise CEH questions linked to Vulnerability Analysis and System Hacking.

Advanced Topics: Wireless, Cloud, IoT, Cryptography practice questions

Sharpen your CEH knowledge of Advanced Topics: Wireless, Cloud, IoT, Cryptography.

Cryptography and Malware Analysis practice questions

Targeted CEH practice covering Cryptography and Malware Analysis.

Footprinting and Reconnaissance practice questions

Targeted CEH practice covering Footprinting and Reconnaissance.

Network and Web Application Attacks practice questions

Targeted CEH practice covering Network and Web Application Attacks.

Enumeration and System Hacking practice questions

Practise CEH questions linked to Enumeration and System Hacking.

Footprinting, Reconnaissance and Scanning practice questions

Sharpen your CEH knowledge of Footprinting, Reconnaissance and Scanning.

Social Engineering and Physical Security practice questions

Practise CEH questions linked to Social Engineering and Physical Security.

Malware, Social Engineering and Network Attacks practice questions

Sharpen your CEH knowledge of Malware, Social Engineering and Network Attacks.

Web Application and Injection Attacks practice questions

Sharpen your CEH knowledge of Web Application and Injection Attacks.

Frequently asked questions

What does the CEH exam test about Cryptography and Malware Analysis?
Match cryptographic primitives to their properties: PFS requires ephemeral Diffie-Hellman variants, not static RSA. For malware, correlate key length and ciphertext size to infer the algorithm. For keyloggers, distinguish hardware from software and choose physical or USB-level detection accordingly.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cryptography and Malware Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the Cryptography and Malware Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CEH topics?
Use the topic links above to move to related areas, or go back to the CEH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CEH exam covers. They are not copied from any real exam or dump site.