Courseiva

312-39 · domain

Forensic Investigation And Malware Analysis

Practise Certified SOC Analyst (312-39) Forensic Investigation And Malware Analysis practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

15 questions3 easy6 medium6 hard

Focused practice

Practice Forensic Investigation And Malware Analysis questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Forensic Investigation And Malware Analysis

Forensic Investigation And Malware Analysis questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Forensic Investigation And Malware Analysis exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Forensic Investigation And Malware Analysis questions (15)

Click any question to see the full explanation, or start a practice session above.

1

You are investigating a file-less malware infection. Where in the Windows Registry would you look to identify common persistence mechanisms used by malicious scripts?

Medium
2

A SOC analyst is analyzing a suspicious email attachment. The analyst wants to extract URLs and embedded files without detonating the payload in a full sandbox. Which tool is recommended for this type of file parsing?

Medium
3

When performing static analysis of a malicious binary, which THREE indicators should an analyst typically look for?

Medium
4

In the context of malware analysis, which TWO of the following are primary differences between static and dynamic analysis?

Hard
5

While investigating a potential malware infection, a SOC analyst needs to determine if a specific binary has been analyzed by the security community before. Which platform is the industry standard for checking the reputation of a file hash across dozens of antivirus engines?

Easy
6

During an incident response, you identify a persistent malware process. You need to see exactly which files and registry keys the process is touching in real-time. Which Sysinternals tool provides this capability?

Medium
7

A SOC analyst is analyzing a suspected PowerShell-based attack. Which Windows log event ID is primarily used to log executed PowerShell command blocks?

Easy
8

Which TWO types of evidence are classified as 'volatile' and should be captured first during a forensic investigation?

Medium
9

When conducting a forensic investigation, you need to ensure the integrity of the collected digital evidence. What is the most critical step to perform immediately after copying the original media to a forensic workstation?

Hard
10

A SOC analyst is preparing to collect digital evidence from a compromised server. Which TWO actions must be documented to maintain a proper Chain of Custody?

Easy
11

When analyzing network traffic associated with a malware C2 channel, you observe encrypted traffic. Which approach allows you to inspect the content of this traffic without the malware's private key?

Hard
12

You are performing static analysis on an suspicious executable. You want to view the imported functions, strings, and headers without executing the code. Which tool is most appropriate for this task?

Medium
13

You have captured a malicious binary and are performing dynamic analysis. You observe the malware attempting to resolve a domain that you want to intercept. Which tool allows you to simulate a DNS server response to redirect the malware traffic to a local analysis machine?

Hard
14

An analyst is investigating a compromised system. Which THREE of the following artifacts are commonly checked for indicators of persistence?

Hard
15

You are examining a suspicious file and suspect it is packed (obfuscated). Which technique or tool helps identify if a file is likely packed?

Hard

Frequently asked questions

What does the Forensic Investigation And Malware Analysis domain cover on the 312-39 exam?
Forensic Investigation And Malware Analysis questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 15 Forensic Investigation And Malware Analysis questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Forensic Investigation And Malware Analysis questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-csa ECCOUNCIL-CSA forensic investigation and malware analysis Practice Questions