Courseiva

312-39 · topic practice

Forensic Investigation And Malware Analysis practice questions

Practise Certified SOC Analyst (312-39) Forensic Investigation And Malware Analysis practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
16 questionsDomain: Forensic Investigation And Malware Analysis

What the exam tests

What to know about Forensic Investigation And Malware Analysis

Forensic Investigation And Malware Analysis questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Forensic Investigation And Malware Analysis exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Forensic Investigation And Malware Analysis questions

16 questions · select your answer, then reveal the explanation

A SOC analyst needs to capture volatile memory for a forensic investigation on a suspected compromised Windows workstation. Which command-line tool, when executed with the appropriate privilege level, allows for the acquisition of a physical RAM image?

While investigating a potential malware infection, a SOC analyst needs to determine if a specific binary has been analyzed by the security community before. Which platform is the industry standard for checking the reputation of a file hash across dozens of antivirus engines?

Question 3hardmultiple choice
Read the full DNS explanation →

You have captured a malicious binary and are performing dynamic analysis. You observe the malware attempting to resolve a domain that you want to intercept. Which tool allows you to simulate a DNS server response to redirect the malware traffic to a local analysis machine?

During an incident response, you identify a persistent malware process. You need to see exactly which files and registry keys the process is touching in real-time. Which Sysinternals tool provides this capability?

A SOC analyst is analyzing a suspicious email attachment. The analyst wants to extract URLs and embedded files without detonating the payload in a full sandbox. Which tool is recommended for this type of file parsing?

You are performing static analysis on an suspicious executable. You want to view the imported functions, strings, and headers without executing the code. Which tool is most appropriate for this task?

You are examining a suspicious file and suspect it is packed (obfuscated). Which technique or tool helps identify if a file is likely packed?

When conducting a forensic investigation, you need to ensure the integrity of the collected digital evidence. What is the most critical step to perform immediately after copying the original media to a forensic workstation?

When analyzing network traffic associated with a malware C2 channel, you observe encrypted traffic. Which approach allows you to inspect the content of this traffic without the malware's private key?

When performing static analysis of a malicious binary, which THREE indicators should an analyst typically look for?

You are investigating a file-less malware infection. Where in the Windows Registry would you look to identify common persistence mechanisms used by malicious scripts?

Which TWO types of evidence are classified as 'volatile' and should be captured first during a forensic investigation?

A SOC analyst is preparing to collect digital evidence from a compromised server. Which TWO actions must be documented to maintain a proper Chain of Custody?

An analyst is investigating a compromised system. Which THREE of the following artifacts are commonly checked for indicators of persistence?

A SOC analyst is analyzing a suspected PowerShell-based attack. Which Windows log event ID is primarily used to log executed PowerShell command blocks?

In the context of malware analysis, which TWO of the following are primary differences between static and dynamic analysis?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Forensic Investigation And Malware Analysis sessions

Start a Forensic Investigation And Malware Analysis only practice session

Every question in these sessions is drawn from the Forensic Investigation And Malware Analysis domain — nothing else.

Related practice questions

Related 312-39 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 312-39 exam test about Forensic Investigation And Malware Analysis?
Forensic Investigation And Malware Analysis questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Forensic Investigation And Malware Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the Forensic Investigation And Malware Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 312-39 topics?
Use the topic links above to move to related areas, or go back to the 312-39 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 312-39 exam covers. They are not copied from any real exam or dump site.