Courseiva

212-89 · topic practice

Malware Incidents practice questions

Practise Certified Incident Handler (212-89) Malware Incidents practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Malware Incidents

What the exam tests

What to know about Malware Incidents

Malware Incidents questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Malware Incidents exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Malware Incidents questions

20 questions · select your answer, then reveal the explanation

You are using Wireshark to analyze traffic from an infected host. You notice consistent beaconing activity to an external IP on port 443. How do you isolate this traffic in your capture?

You are analyzing a malware sample using Cuckoo Sandbox. The report shows the malware is attempting to modify the 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run' registry key. What is the intent of this activity?

You are performing a live memory analysis using Volatility 3. You suspect a rootkit is hiding processes. Which plugin should you run to compare the process list from the EPROCESS block with the thread scheduler's list?

A malware infection has encrypted several network shares. You decide to restore from backups. What is the most critical step to perform before restoring data to the production environment?

You are using YARA to detect a specific strain of ransomware. You want to match a file if it contains a specific hex string OR a specific string value. How do you construct this in your rule?

During an incident, you need to isolate a compromised workstation from the network immediately. Which action is the most effective containment strategy while preserving volatile memory?

An analyst is reviewing logs from an EDR solution. They see a 'process hollowing' event. What is the primary purpose of this malware technique?

During a malware incident response, you identify a suspicious process with PID 4452 using Sysinternals Process Explorer. You need to verify the file's reputation before isolation. Which action allows you to do this directly within the tool?

You are analyzing a malware sample in a lab. You notice the malware uses the 'CreateRemoteThread' API. What is the objective of this malware activity?

You are reviewing logs from an EDR and see an indicator of 'Living off the Land' (LotL). Which tool usage would be considered an LotL attack?

Question 11mediummultiple choice
Read the full Malware Incidents explanation →

You have identified an infected machine and need to perform a memory dump before it is wiped. Which tool is the industry standard for acquiring a full memory dump on a Windows machine for incident response?

A user reports their system is running slowly, and you observe a suspicious file in 'C:\Users\[User]\AppData\Local\Temp'. What is the most appropriate first step in your investigation?

Question 13mediummultiple choice
Read the full Malware Incidents explanation →

After eradicating a malware infection, you need to ensure the system is hardened against future occurrences. Which action is most effective against fileless malware?

An incident handler is analyzing a malware incident that used a phishing email. What is the most important field to check in the email header to determine the true origin of the email?

You are analyzing a malware sample that uses Domain Generation Algorithms (DGA). What is the primary purpose of DGA in malware?

Question 16mediummultiple choice
Read the full Malware Incidents explanation →

A malware sample was found to use a 'Mutex' to ensure only one instance of the malware runs at a time. What tool would you use to find the Mutex name on an infected host?

Which document is essential to maintain during a malware incident to ensure accountability and track the actions taken by the incident response team?

You are performing forensic analysis on a suspicious file. You need to determine if it is a packed executable. Which tool is most effective for viewing the file's section headers to identify anomalies?

Question 19mediummultiple choice
Read the full Malware Incidents explanation →

You suspect a malware incident caused unauthorized data exfiltration. Which log source is most useful to identify the destination IP of the exfiltrated data?

A system has been infected by a worm that is spreading across the network. What is the most immediate action to stop the spread?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Malware Incidents sessions

Start a Malware Incidents only practice session

Every question in these sessions is drawn from the Malware Incidents domain — nothing else.

Related practice questions

Related 212-89 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 212-89 exam test about Malware Incidents?
Malware Incidents questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Malware Incidents questions in a focused session?
Yes — the session launcher on this page draws every question from the Malware Incidents domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 212-89 topics?
Use the topic links above to move to related areas, or go back to the 212-89 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 212-89 exam covers. They are not copied from any real exam or dump site.