← All CCT Flashcard Decks

Digital Forensics & Malware Analysis Flashcards

7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Digital Forensics & Malware Analysis flashcards as text
  1. What distinguishes dynamic malware analysis from static analysis?

    Answer: Dynamic analysis executes the sample in a controlled environment to observe behavior

    Dynamic analysis detonates the malware in an isolated sandbox or VM to observe real-time behaviors such as file creation, registry changes, and network calls.

  2. A malware sample modifies the Windows registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Run. What is the likely purpose?

    Answer: Establishing persistence so the malware survives reboots

    The Run registry key causes listed programs to execute automatically at user logon, making it a common persistence mechanism for malware.

  3. Which sandbox tool is widely used for automated dynamic malware analysis and generates detailed behavioral reports?

    Answer: Cuckoo Sandbox

    Cuckoo Sandbox is an open-source automated malware analysis system that detonates samples and produces reports on file, network, and process activity.

  4. A process injects code into explorer.exe to hide its presence. What technique is this?

    Answer: Process injection

    Process injection involves inserting malicious code into the address space of a legitimate running process to evade detection and inherit its trust level.

  5. Which Wireshark display filter would capture only DNS traffic for network forensics?

    Answer: dns

    The 'dns' display filter in Wireshark specifically isolates DNS protocol traffic regardless of the transport layer, making it the most direct filter.

  6. Malware uses domain generation algorithms (DGA) to communicate with its C2 server. What is the main benefit to the attacker?

    Answer: Generating random domains daily to evade static blocklists

    DGA dynamically generates many pseudo-random domain names, so defenders cannot block C2 by blacklisting a single domain — the attacker only needs to register one.

  7. Which memory forensics framework is most commonly used to analyze RAM dumps and detect injected processes, hidden drivers, and network connections?

    Answer: Volatility

    Volatility is the industry-standard open-source memory forensics framework that can extract processes, network artifacts, and detect common evasion techniques from RAM images.