โ† All CySA+ Test Flashcard Decks

CySA+ Test Malware Analysis Flashcards

6 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CySA+ Test Malware Analysis flashcards as text
  1. Which malware analysis technique executes a sample in an isolated environment to observe its behavior without risking production systems?

    Answer: Dynamic analysis

    Dynamic analysis runs malware in a sandbox to observe runtime behavior such as file writes, network calls, and registry changes.

  2. A CySA+ analyst uses a disassembler to examine malware without executing it. This is an example of which analysis type?

    Answer: Static analysis

    Static analysis inspects malware code, strings, and structure without running it, often using tools like disassemblers and hex editors.

  3. Which indicator would BEST suggest a piece of malware is performing process injection?

    Answer: Unexpected DLL loaded in a legitimate process memory space

    Process injection is characterized by a foreign DLL or code being loaded into a legitimate process's memory space to evade detection.

  4. Which type of malware is specifically designed to record keystrokes and transmit them to an attacker?

    Answer: Keylogger

    A keylogger captures and logs keyboard input, often to steal credentials or sensitive information.

  5. An analyst identifies malware that modifies the Master Boot Record (MBR). Which malware classification BEST fits this behavior?

    Answer: Bootkit

    A bootkit infects the MBR or boot sector, loading before the OS and persisting across reboots.

  6. Which tool is commonly used during static malware analysis to extract human-readable text embedded in a binary?

    Answer: strings utility

    The strings utility extracts printable character sequences from binary files, often revealing URLs, registry keys, or commands.