Courseiva

212-89 · domain

Malware Incidents

Practise Certified Incident Handler (212-89) Malware Incidents practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

34 questions9 easy14 medium11 hard

Focused practice

Practice Malware Incidents questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Malware Incidents

Malware Incidents questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Malware Incidents exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Malware Incidents questions (34)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE of the following are considered 'behavioral' indicators of a malware infection?

Hard
2

You are reviewing logs from an EDR and see an indicator of 'Living off the Land' (LotL). Which tool usage would be considered an LotL attack?

Hard
3

You are analyzing a malware sample that uses 'API Hooking'. What is the goal of this technique?

Hard
4

You have identified a malicious DLL that is being loaded by a legitimate process. Which tool allows you to view which DLLs are loaded by a specific process?

Medium
5

You are analyzing a malware sample that uses Domain Generation Algorithms (DGA). What is the primary purpose of DGA in malware?

Hard
6

A malware infection has encrypted several network shares. You decide to restore from backups. What is the most critical step to perform before restoring data to the production environment?

Medium
7

When eradicating malware, which TWO of the following steps are essential to ensure the host is fully cleaned and the entry point is secured?

Medium
8

An analyst is reviewing logs from an EDR solution. They see a 'process hollowing' event. What is the primary purpose of this malware technique?

Easy
9

You are analyzing a malware sample using Cuckoo Sandbox. The report shows the malware is attempting to modify the 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run' registry key. What is the intent of this activity?

Medium
10

You are analyzing a malware sample in a lab. You notice the malware uses the 'CreateRemoteThread' API. What is the objective of this malware activity?

Hard
11

You are using Wireshark to analyze traffic from an infected host. You notice consistent beaconing activity to an external IP on port 443. How do you isolate this traffic in your capture?

Medium
12

When analyzing a potentially malicious script, which THREE of the following techniques help in deobfuscating the code?

Hard
13

You have identified an infected machine and need to perform a memory dump before it is wiped. Which tool is the industry standard for acquiring a full memory dump on a Windows machine for incident response?

Medium
14

A malware sample was found to use a 'Mutex' to ensure only one instance of the malware runs at a time. What tool would you use to find the Mutex name on an infected host?

Medium
15

A system has been infected by a worm that is spreading across the network. What is the most immediate action to stop the spread?

Easy
16

Which THREE of the following are effective methods for protecting backup systems from being encrypted by ransomware?

Medium
17

During an incident, you need to isolate a compromised workstation from the network immediately. Which action is the most effective containment strategy while preserving volatile memory?

Easy
18

During a malware incident response, you identify a suspicious process with PID 4452 using Sysinternals Process Explorer. You need to verify the file's reputation before isolation. Which action allows you to do this directly within the tool?

Medium
19

You are performing forensic analysis on a suspicious file. You need to determine if it is a packed executable. Which tool is most effective for viewing the file's section headers to identify anomalies?

Hard
20

You are using YARA to detect a specific strain of ransomware. You want to match a file if it contains a specific hex string OR a specific string value. How do you construct this in your rule?

Hard
21

You are performing a live memory analysis using Volatility 3. You suspect a rootkit is hiding processes. Which plugin should you run to compare the process list from the EPROCESS block with the thread scheduler's list?

Hard
22

During the 'Recovery' phase of the malware incident, what must be done to ensure the environment is safe before reconnecting the restored systems?

Easy
23

A user reports their system is running slowly, and you observe a suspicious file in 'C:\Users\[User]\AppData\Local\Temp'. What is the most appropriate first step in your investigation?

Easy
24

When reviewing network traffic for C2 communication, which THREE of the following indicators are commonly observed?

Hard
25

Which THREE of the following tools would be most effective for performing live memory forensics on a compromised Windows workstation?

Hard
26

Which TWO of the following sources of information are most helpful for building an Indicators of Compromise (IoC) list during an investigation?

Easy
27

Which TWO of the following activities are considered 'Eradication' steps in the incident response lifecycle?

Easy
28

Which THREE of the following indicators are found in email-based malware delivery?

Medium
29

After eradicating a malware infection, you need to ensure the system is hardened against future occurrences. Which action is most effective against fileless malware?

Medium
30

You suspect a file on a Linux server is malicious. What command can you use to obtain the MD5 hash of the file?

Medium
31

During a malware analysis, which TWO of the following indicators are typically used to identify persistence mechanisms in the Windows registry?

Medium
32

An incident handler is analyzing a malware incident that used a phishing email. What is the most important field to check in the email header to determine the true origin of the email?

Easy
33

You suspect a malware incident caused unauthorized data exfiltration. Which log source is most useful to identify the destination IP of the exfiltrated data?

Medium
34

Which document is essential to maintain during a malware incident to ensure accountability and track the actions taken by the incident response team?

Easy

Frequently asked questions

What does the Malware Incidents domain cover on the 212-89 exam?
Malware Incidents questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 34 Malware Incidents questions in the 212-89 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Malware Incidents questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-ecih ECCOUNCIL-ECIH malware incidents Practice Questions