Courseiva

CCNA Malware and AI-Assisted Investigations Questions

20 questions · Malware and AI-Assisted Investigations · All types, answers revealed

1
MCQmedium

An analyst notices that an AI-powered detection tool is flagging legitimate administrative PowerShell scripts as malicious. Which approach should the analyst take to improve model precision?

A.Disable the detection rule entirely until the AI update is released.
B.Update the training set to include these scripts as 'benign' examples.
C.Increase the sensitivity threshold of the AI model to ignore all PowerShell activity.
D.Replace the AI model with a static signature-based detection system.
AnswerB

Adding false positives to the training set allows the model to learn the boundary between legitimate admin activity and malicious PowerShell usage. This process of continuous learning improves model accuracy over time, significantly reducing the burden on the SOC by filtering out expected, non-malicious behavior from the daily alert queue.

Why this answer

Model precision is improved by incorporating false positives into the training loop. By labeling these administrative scripts correctly, the analyst provides the model with the necessary 'negative' examples to learn the nuances between legitimate management tasks and malicious activity. This reduces future noise, allowing the incident response team to focus on actual threats rather than spending time triaging recurring, known-good administrative actions that currently trigger alerts.

Exam trap

Candidates frequently suggest adjusting global thresholds or rewriting the entire detection engine, missing the direct solution of retraining the model with specific false-positive samples.

2
MCQeasy

A junior analyst is using an AI-powered malware analysis tool to examine a suspicious executable. The tool provides a summary indicating that the file is 'likely malicious' with a confidence score of 65%. The analyst is unsure how to proceed. According to incident response best practices, what should the analyst do NEXT?

A.Escalate to a senior analyst and wait for further instructions.
B.Treat the file as malicious and immediately delete it from all systems.
C.Ignore the alert because the confidence score is below 90%.
D.Perform additional manual analysis, such as static and dynamic examination, to confirm the tool's findings.
AnswerD

Manual analysis provides independent verification of the AI tool's assessment. Static analysis can reveal suspicious imports or strings, while dynamic analysis in a sandbox can show actual behavior. This approach ensures that decisions are based on multiple sources of evidence, reducing the risk of false positives or negatives.

Why this answer

When an AI tool provides a low-confidence result, the analyst should validate it through manual analysis. This involves static and dynamic techniques to confirm maliciousness. Deleting files or ignoring alerts without verification can lead to errors.

Escalation without initial investigation may delay response.

Exam trap

The trap here is either blindly trusting or dismissing the AI tool's output without independent verification, when the correct approach is to corroborate with manual analysis.

3
MCQmedium

An analyst is training a machine learning model to classify malware families. Which data preparation technique is most critical to prevent bias in the classification results?

A.Including only the most recent malware samples in the dataset.
B.Manually labeling only a small subset of the total available samples.
C.Ensuring a balanced distribution of samples across all malware classes.
D.Removing all features that contain obfuscated code or strings.
AnswerC

Balanced data prevents the model from favoring majority classes. By providing an equal representation of various malware families, the algorithm learns the distinct features of each, leading to higher accuracy during inference. This balanced approach is critical for maintaining high detection rates across diverse threat vectors during active incident investigations.

Why this answer

Data balance is the foundation of effective machine learning. If a training set is heavily skewed toward one malware family, the model will develop a prediction bias that favors that family, leading to poor classification performance for novel variants. This matters because biased models provide a false sense of security, causing investigators to overlook emerging threats that do not fit the over-represented patterns learned during the training phase.

Exam trap

Candidates often confuse data balancing with feature selection or hyperparameter tuning, assuming that removing noise or adjusting model complexity solves class imbalance issues.

4
Multi-Selectmedium

You are leading an incident response effort against a sophisticated adversary who uses AI-generated polymorphic malware that changes its code signature on each execution. Your team employs AI-assisted tools for detection and analysis. Which TWO of the following techniques are MOST effective for identifying and tracking this malware across multiple hosts? (Choose two.)

Select 2 answers
A.Perform regular full-disk antivirus scans on all endpoints to detect known signatures.
B.Monitor for anomalous process behavior, such as unexpected parent-child relationships or network connections.
C.Use file hash-based indicators of compromise (IOCs) to search for the malware across the enterprise.
D.Rely on the AI-assisted EDR's automatic quarantine of files with low reputation scores.
E.Extract and analyze unique strings or code patterns that persist across variants to create YARA rules.
AnswersB, E

Behavioral monitoring focuses on what the malware does rather than its code signature. Polymorphic malware still exhibits malicious behaviors like creating unusual processes, connecting to C2 servers, or modifying registry keys. AI-assisted tools can baseline normal behavior and flag deviations, making this an effective detection method even when signatures change.

Why this answer

Behavioral monitoring and YARA rules based on persistent code patterns are effective because they do not rely on static signatures. Behavioral analysis detects malicious actions regardless of code changes, while YARA rules can target invariant parts of the malware. Hash-based IOCs, reputation scores, and traditional antivirus are easily evaded by polymorphic malware.

Exam trap

The trap here is assuming that hash-based IOCs or traditional antivirus can track polymorphic malware, when in fact they are easily bypassed by code changes.

5
Multi-Selecthard

Which TWO of the following strategies are most effective when using AI tools to assist in the analysis of large-scale, automated malware logs?

Select 2 answers
A.Provide the AI with the full, unfiltered enterprise log database without context.
B.Use the AI to identify outliers in communication patterns compared to historical baselines.
C.Task the AI with summarizing log files based on established MITRE ATT&CK techniques.
D.Rely on the AI to automatically perform incident remediation without verification.
E.Instruct the AI to ignore all non-standard timestamps to simplify the output.
AnswersB, C

AI excels at identifying statistical deviations in large datasets. By comparing current traffic patterns against established historical baselines, the model can highlight unusual connections, such as unexpected beaconing or data exfiltration attempts. This narrows the scope for the responder, allowing them to focus investigative efforts on high-probability malicious events rather than raw logs.

Why this answer

Effective AI-assisted log analysis requires a balance of automation and human verification. By focusing on pattern recognition and outlier detection, investigators can rapidly surface anomalies that manual review would miss. These strategies matter because modern malware generates massive datasets; relying solely on manual inspection is unsustainable, while relying solely on AI without defined parameters leads to alert fatigue and significant false positive rates that obscure the true threat actor's activities.

Exam trap

Candidates often suggest using AI for automated remediation or full-scale log deletion, ignoring that the question specifically asks for analysis strategies that maintain human oversight and focus on identifying patterns.

6
MCQhard

A GCIH incident handler is investigating a Linux server that an AI-based anomaly detector flagged for unusual outbound traffic. The handler suspects the server is beaconing to a C2 server but the traffic is encrypted and the beacon interval appears randomized. The handler has a packet capture and wants to apply a technique that can identify the beaconing pattern despite the randomization. Which approach should the handler use?

A.Perform frequency analysis on the inter-arrival times of outbound connections to the suspected destination.
B.Decrypt the TLS session using the server's private key and search the payload for known C2 strings.
C.Run a signature-based IDS rule set updated with the latest C2 domain blocklist against the packet capture.
D.Inspect the TLS certificate presented by the suspected C2 server for a self-signed or mismatched common name.
AnswerA

Beaconing, even with randomized intervals, often retains a statistical signature such as a base interval with jitter or a periodic component. Frequency analysis on inter-arrival times can reveal that underlying periodicity, distinguishing C2 traffic from routine user-driven connections. This technique works on encrypted traffic because it analyzes timing metadata rather than payload, directly addressing the randomized beacon interval challenge.

Why this answer

When beacon intervals are randomized, the payload is encrypted, and signatures are unavailable, timing metadata becomes the most reliable signal. Frequency analysis on inter-arrival times can expose an underlying periodic component or a base interval with jitter, which is characteristic of beaconing. Certificate inspection and signature matching depend on known-bad artifacts, and TLS decryption is impractical without keys, so timing analysis is the correct approach.

Exam trap

The trap here is assuming that encrypted C2 cannot be analyzed, when timing metadata like inter-arrival intervals remains visible and is often sufficient to detect beaconing.

7
MCQmedium

Refer to the exhibit. The log shows a low-confidence alert from an AI tool. How should an incident responder proceed?

A.Follow the suggestion and isolate the host as instructed by the system.
B.Conduct manual investigation of the host and network traffic to verify.
C.Log the event as a false positive and disable the detection rule.
D.Wait for the AI to provide more logs before making a decision.
AnswerB

Manual validation is the only safe way to handle low-confidence AI alerts. By verifying the network traffic patterns and host process logs, the responder can determine if the alert is a genuine threat or a statistical anomaly. This preserves the operational uptime while ensuring that the organization's security posture remains robust and accurate.

Why this answer

With a confidence score of 0.45, the AI is expressing high uncertainty, effectively indicating that the detection is not reliable enough for automated action. The responder must perform a manual investigation—such as checking firewall logs, host artifacts, or process trees—to validate the alert before taking disruptive actions. This ensures that the incident response process remains grounded in high-fidelity evidence rather than reacting to 'noisy' but potentially incorrect AI-generated suggestions.

Exam trap

Candidates often assume that a low-confidence alert can be ignored or automatically dismissed, failing to realize that even 'low' probability threats still require human triage to confirm or rule out malicious activity.

8
MCQmedium

Which capability is most important for a modern incident response team to maintain when integrating AI tools into their workflow?

A.The ability to programmatically fine-tune neural network architectures.
B.The ability to perform manual forensic validation of AI-detected alerts.
C.The ability to automate the entire incident lifecycle without human oversight.
D.The ability to replace all legacy detection tools with AI-based solutions.
AnswerB

Manual forensic validation ensures that the responder can verify the 'why' and 'how' behind an AI alert. This is critical for preventing false-positive-driven downtime and for conducting thorough root cause analysis. Without the ability to manually confirm findings, the incident response team cannot effectively defend the enterprise against sophisticated, evasive, or novel threats.

Why this answer

The ability to perform manual forensic validation is the cornerstone of effective incident response, even in an era of AI. AI tools serve as force multipliers to speed up analysis, but the ultimate responsibility for accuracy and evidence integrity remains with the human responder. Maintaining these skills prevents over-reliance on automated tools, which is critical for handling novel or complex threats that the AI models were never trained to detect.

Exam trap

Candidates often prioritize 'AI proficiency' or 'speed of automation' as the most important capability, missing that the ability to validate the AI is the only way to ensure the incident response remains accurate.

9
MCQeasy

A junior incident handler is reviewing an alert from an AI-powered email security gateway that flagged a message as a likely AI-generated phishing attempt. The gateway's model outputs a confidence score but no explanation. The handler wants to gather corroborating evidence from the message headers and body to support the classification before escalating. Which artifact would best help the handler verify that the message was generated or augmented by an AI tool?

A.The sender's display name and the reply-to address mismatch.
B.The SPF and DKIM authentication results in the headers.
C.The Received header chain showing the message's relay path.
D.The message body's writing style and any embedded AI watermark or metadata.
AnswerD

AI-generated text often exhibits consistent stylistic patterns, and some providers embed watermarks or metadata in generated content. Examining the body for unnatural uniformity, repeated phrasing, or embedded markers can corroborate the gateway's classification. This is the most direct artifact for validating that the content itself was AI-generated, which is exactly what the handler needs before escalating the alert.

Why this answer

To corroborate an AI-generation classification, the handler should look at the content itself, since AI-written text often shows distinctive stylistic uniformity and may carry watermarks or metadata. Header-based artifacts like SPF, DKIM, and Received chains address origin and authentication, not authorship. Focusing on the body's style and embedded markers directly supports or refutes the gateway's model output before escalation.

Exam trap

The trap here is conflating phishing indicators like SPF failures or reply-to mismatches with evidence of AI authorship, when those address origin and spoofing instead.

10
MCQhard

An attacker has compromised a host and established persistence using a malicious scheduled task that executes an encoded PowerShell command. The command downloads a second-stage payload from a legitimate cloud storage service. Your AI-assisted EDR has flagged the activity but provided only a low-confidence alert. As the incident responder, you need to determine the next investigative step. Which of the following actions is MOST likely to yield actionable intelligence about the second-stage payload?

A.Immediately isolate the host and rebuild it from a known-good image.
B.Decode the PowerShell command and extract the URL to retrieve the payload for analysis.
C.Review the scheduled task's XML definition to identify the author and creation time.
D.Run a full antivirus scan on the host to detect and remove the second-stage payload.
AnswerB

Decoding the PowerShell command reveals the exact URL used to download the second-stage payload. Retrieving and analyzing that payload in a sandbox will provide details about its capabilities, C2 infrastructure, and potential indicators. This directly advances the investigation by obtaining the actual malware for further study, rather than relying on low-confidence alerts.

Why this answer

Decoding the PowerShell command and retrieving the payload is the most direct way to gain intelligence. It allows you to analyze the malware, extract IOCs, and understand the attack chain. Other options either destroy evidence, are unlikely to detect the payload, or provide limited context.

Exam trap

The trap here is focusing on containment or scanning without first extracting and analyzing the payload, which is essential for understanding the threat and preventing recurrence.

11
MCQhard

An AI-assisted investigation tool summarizes a week of EDR telemetry and reports that a workstation 'likely performed credential dumping.' The summary cites no specific process, command line, or timestamp. What should the incident handler do first?

A.Escalate to management and legal teams because credential dumping implies a reportable breach.
B.Retrain or tune the AI model because its summary lacks supporting detail.
C.Query the underlying EDR data for LSASS access events and suspicious process lineage to validate the AI claim.
D.Isolate the workstation immediately to prevent lateral movement.
AnswerC

The AI summary is an unverified inference, so the handler must pivot to the raw EDR telemetry that the model used. Searching for LSASS handle requests, known dumping tools like Mimikatz or ProcDump, and unusual parent-child process relationships provides concrete evidence. This validation step confirms or refutes the claim and produces the specific artifacts needed for escalation and containment decisions.

Why this answer

AI-generated summaries are inferences that must be validated against source telemetry before action. The handler should query EDR for LSASS access, known credential dumping tool indicators, and suspicious process ancestry to confirm or refute the claim. This produces concrete evidence for escalation and avoids both unnecessary containment and missed detection.

Validation is the foundational step in any AI-assisted investigation.

Exam trap

The trap here is treating an AI summary as a confirmed finding and acting on containment or escalation without validating the underlying telemetry.

12
MCQhard

When investigating an AI-generated spear-phishing campaign, what is the most effective indicator to look for that suggests the content was created by a Large Language Model (LLM)?

A.Presence of multiple spelling and grammatical errors.
B.Consistent, overly formal tone that lacks specific organizational context.
C.Inclusion of malicious code within the email header metadata.
D.The email is sent from a known, compromised account.
AnswerB

AI models tend to default to a polite, formal, and generic tone when instructed to write persuasive emails. They often lack the 'tribal knowledge' or specific cultural context of the target organization. This generic nature is a strong indicator of AI generation, as human-written phishing often contains specific internal references or unique colloquialisms.

Why this answer

LLMs often produce text that is grammatically perfect but lacks the specific, idiosyncratic context or 'human touch' of targeted communication. Identifying these characteristics requires comparing the suspect emails against known communication baselines of the purported sender. Understanding these patterns is crucial because AI can now produce highly convincing phishing lures at scale, requiring responders to look past the superficial professionalism to find the lack of contextual depth or intent alignment.

Exam trap

Candidates often look for 'spelling errors' or 'bad grammar,' forgetting that modern LLMs are highly proficient at generating grammatically perfect text that lacks specific, localized organizational context.

13
MCQhard

An analyst discovers that an attacker is using AI to dynamically change the command-and-control (C2) infrastructure based on defensive responses. Which IR strategy is best suited to disrupt this behavior?

A.Maintain the current defense and wait for the C2 to remain static.
B.Implement proactive deception techniques to feed the attacker's AI false data.
C.Block all outbound traffic at the perimeter to stop the communication.
D.Perform a full system wipe of all endpoints involved in the C2 network.
AnswerB

Feeding an adversary's AI false data creates a poisoned feedback loop. By injecting deceptive signals, the responder can cause the attacker's infrastructure to adapt in ways that are disadvantageous, such as routing to honeypots. This forces the adversary to waste resources and reveals their infrastructure, which can then be systematically blocked or neutralized.

Why this answer

The most effective way to counter dynamic, AI-driven infrastructure is to implement 'proactive deception' and 'automated environment hardening.' By creating a moving target environment, the responder forces the attacker's AI to constantly adjust to false or unstable indicators. This disrupts the adversary's ability to maintain a persistent connection, effectively neutralizing the advantage gained by their automated infrastructure adjustments during the incident containment phase.

Exam trap

Candidates frequently choose passive monitoring or static blocking tools, failing to recognize that AI-driven threats adapt too quickly for static defenses to be effective.

14
Multi-Selecthard

Which THREE of the following are essential components of an effective AI-assisted malware hunting strategy?

Select 3 answers
A.Continuous ingestion of high-quality, normalized telemetry data.
B.A feedback loop where analyst findings refine future AI model detection.
C.Eliminating all manual review to maximize the hunting speed.
D.Focusing exclusively on known malware signatures for speed.
E.Regular testing of the model against adversarial evasion attempts.
AnswersA, B, E

AI models are only as good as the data they process. High-quality, normalized telemetry from across the environment is essential for the AI to identify meaningful patterns. Inconsistent or poor-quality logs lead to missed detections and high false-positive rates, rendering even the most sophisticated AI models ineffective for malware hunting efforts.

Why this answer

Effective malware hunting requires a combination of strong data hygiene, human intuition, and robust analytical loops. AI provides the speed and pattern recognition necessary to handle large volumes of data, but it requires carefully curated inputs and human oversight to remain effective. These components are essential because they ensure that hunting efforts are scalable, reproducible, and aligned with the actual behavioral patterns observed during the adversary's lifecycle within the enterprise environment.

Exam trap

Many test-takers focus exclusively on the AI model's internal capabilities while neglecting the critical importance of data hygiene and the human-in-the-loop feedback mechanisms required for long-term hunting success.

15
MCQhard

During a malware investigation, you discover that the adversary is using an AI model to generate domain names for its command-and-control (C2) infrastructure. The domains appear legitimate and are registered in bulk. Your AI-assisted threat hunting platform uses domain generation algorithm (DGA) detection but is missing these domains. Which of the following is the MOST likely reason for the detection failure?

A.The DGA detection model was trained on older DGA families and cannot recognize AI-generated patterns.
B.The AI model generates domains that are too short to be analyzed by the DGA detection.
C.The C2 traffic is encrypted, preventing the DGA detection from analyzing the domain names.
D.The domains are registered with legitimate registrars, so they are automatically whitelisted.
AnswerA

AI-generated domains may follow different statistical patterns than traditional DGAs. If the detection model was trained primarily on known DGA families, it may not generalize to novel AI-generated domains. This is a common limitation of machine learning models when faced with evolving threats, requiring retraining with new data.

Why this answer

AI-generated domains may not match the patterns learned by a DGA detection model trained on traditional algorithms. The model's inability to recognize novel AI-generated patterns is the most likely cause. Other factors like registration, encryption, or length are less relevant to DGA detection.

Exam trap

The trap here is assuming that DGA detection can automatically adapt to AI-generated domains, when in fact it requires retraining on new data to recognize evolving patterns.

16
MCQeasy

An analyst uses an AI assistant to summarize a malware report and generate response steps. Before executing any recommended commands on production systems, what is the most important action?

A.Ask the AI to confirm that its own recommendations are correct.
B.Execute the commands immediately to contain the threat before it spreads.
C.Save the AI output as the official incident record without modification.
D.Verify the commands against authoritative documentation and test them in a non-production environment.
AnswerD

AI assistants can produce plausible but incorrect commands or outdated syntax. Verifying against authoritative vendor documentation and testing in a lab or non-production system prevents accidental disruption of production services. This validation step is essential before executing any AI-recommended action, especially commands that modify system state or delete data.

Why this answer

AI-generated response steps must be treated as suggestions, not instructions. Verifying commands against authoritative documentation and testing them in a non-production environment prevents accidental outages and data loss. This practice preserves production stability and evidence integrity while still allowing the analyst to benefit from AI-assisted summarization and drafting.

Exam trap

The trap here is trusting AI-generated commands as authoritative and executing them on production systems without independent verification.

17
MCQeasy

Which of the following is a classic example of an 'adversarial' attack against an AI-powered detection engine?

A.A distributed denial-of-service attack against the AI server.
B.Adding 'dead' code blocks to hide the malicious payload's intent.
C.Applying minimal, non-functional perturbations to code to cause misclassification.
D.Using stolen credentials to access the AI administration console.
AnswerC

This describes an adversarial perturbation. Attackers use these to exploit the mathematical weaknesses in the way AI models process features. Because the change is minimal and non-functional, the malware continues to behave normally while the AI model incorrectly tags it as legitimate, demonstrating the core mechanism of adversarial machine learning attacks.

Why this answer

Adversarial attacks aim to manipulate the input to an AI model to cause a misclassification. By adding carefully crafted, minimal noise—sometimes called an 'adversarial perturbation'—an attacker can make malicious code appear benign to the model. Recognizing these attacks is vital for incident handlers because it explains why an otherwise robust system might miss a clearly malicious payload that an analyst can easily see with the naked eye.

Exam trap

Students frequently confuse adversarial perturbations designed to evade AI classifiers with traditional network-layer evasion techniques or classic application vulnerabilities like SQL injection.

18
MCQeasy

Which of the following is the primary risk associated with using unvetted AI models for malware signature generation?

A.The model will always generate signatures that are too complex to implement.
B.The model may produce signatures that trigger on benign system binaries.
C.The model will consume excessive processing power on the endpoint.
D.The model will force the malware to evolve into a polymorphic variant.
AnswerB

AI models trained on insufficient or biased data often fail to distinguish between malicious and legitimate system activity. This leads to the generation of false-positive signatures that flag critical OS files. Deploying such signatures in a production environment causes significant operational disruption, effectively creating a self-inflicted denial-of-service attack for the organization.

Why this answer

Using unvetted AI models for signature generation risks creating false signatures that could lead to widespread system instability or denial of service if deployed to endpoint protection platforms. In the context of malware investigation, these tools must be calibrated against known-good and known-bad datasets. Failing to vet the model results in a high false-positive rate, which ultimately undermines the efficacy of the incident response team and wastes valuable time during critical security incidents.

Exam trap

Candidates often identify 'AI model theft' or 'slow processing' as the primary risk, overlooking the operational disaster of a false-positive signature that disables critical business services and system binaries.

19
MCQmedium

Refer to the exhibit. An AI-based EDR identifies a suspicious process chain. Based on the provided JSON output, what is the most appropriate next step for an incident handler?

A.Assume the alert is a false positive due to the common nature of svchost.
B.Immediately isolate the host from the network based on the 0.98 AI score.
C.Examine process memory and network artifacts to confirm malicious injection.
D.Restart the svchost service to terminate the suspicious connection.
AnswerC

Verification is mandatory. By analyzing the memory of the svchost instance and the network connection patterns, the responder confirms whether the process is indeed acting maliciously. This technical validation bridges the gap between an automated alert and actionable intelligence, allowing for a decisive and informed response to the identified threat.

Why this answer

The exhibit shows a clear anomaly where a parent-child relationship (PowerShell spawning svchost) is highly suspicious, especially when associated with an external connection. While the AI score is high, it is a heuristic indicator. The handler must verify this via manual inspection of the process memory and network artifacts to confirm if this is a legitimate system injection or a malicious beacon, ensuring that response actions are based on verified facts.

Exam trap

Candidates often rely purely on high-score AI heuristic alerts or automated verdicts, failing to perform the necessary manual verification of process memory and artifacts.

20
MCQmedium

During an incident, you capture a suspicious binary that evades static detection. You submit it to an AI-based malware analysis platform, which returns a confidence score of 0.55 and flags 'possible packer.' The binary has not yet been detonated. What should you do next?

A.Submit the binary to a dynamic sandbox and correlate its behavior with network and endpoint telemetry.
B.Close the case as a false positive because the confidence score is below 0.75.
C.Immediately block the file hash across all endpoints based on the AI flag.
D.Extract the binary's strings and import table, then make a final determination based on those static artifacts.
AnswerA

A moderate AI confidence score combined with a packer flag is a hypothesis, not a conclusion. Detonating the sample in a sandbox reveals actual behaviors such as persistence, C2 callbacks, and file system changes, which can be correlated with existing network and endpoint logs. This evidence-based validation is the correct next step before containment or escalation decisions.

Why this answer

An AI confidence score of 0.55 with a packer flag is inconclusive, so the responder must validate the hypothesis with behavioral evidence. Dynamic sandbox detonation exposes the malware's actual actions, which can then be correlated with network and endpoint telemetry to confirm malicious intent. Only after corroboration should containment or escalation occur, avoiding both premature blocking and premature dismissal.

Exam trap

The trap here is assuming a low AI confidence score means the file is benign and can be closed without further analysis.

Ready to test yourself?

Try a timed practice session using only Malware and AI-Assisted Investigations questions.