โ† All CySA+ Test Flashcard Decks

CySA+ Test Malware Analysis Flashcards

6 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CySA+ Test Malware Analysis flashcards as text
  1. A sandbox report shows a sample making repeated DNS requests to randomly generated domain names. Which malware technique does this indicate?

    Answer: Domain generation algorithm (DGA)

    A domain generation algorithm (DGA) programmatically creates many pseudo-random domain names to make C2 infrastructure hard to block.

  2. Which artifact should an analyst examine to identify persistence mechanisms established by malware on a Windows host?

    Answer: HKLM\Software\Microsoft\Windows\CurrentVersion\Run registry key

    The Run registry key is a common persistence location where malware adds entries to execute automatically at startup.

  3. An analyst observes that malware deletes Volume Shadow Copies. Which type of malware MOST commonly uses this technique?

    Answer: Ransomware

    Ransomware deletes Volume Shadow Copies to prevent victims from restoring encrypted files from local backups.

  4. Which memory forensics tool is widely used to analyze malware artifacts from a RAM dump?

    Answer: Volatility

    Volatility is the industry-standard open-source framework for memory forensics, capable of extracting processes, DLLs, and network connections from RAM dumps.

  5. A CySA+ analyst observes that a malware sample uses HTTPS to communicate with its C2 server, making traffic appear legitimate. Which technique is this?

    Answer: Encrypted C2 channel

    Using HTTPS for C2 communication blends malicious traffic with normal web traffic, making it harder to detect via inspection.

  6. Which hashing algorithm is MOST commonly used to generate file reputation hashes (IOCs) for malware samples?

    Answer: SHA-256

    SHA-256 is the standard for malware IOC hashing due to its collision resistance and wide adoption in threat intelligence platforms.