Unit 6: Analysis of Malware - Subjective Questions

INT250 — Digital Evidence Analysis • Practice Questions with Detailed Answers

20 questions

1

Define malware. Explain the major characteristics that distinguish malware from legitimate software.

2

Explain the common techniques used by attackers to spread malware.

3

Describe how social engineering, phishing, and drive-by downloads are used together in a malware infection campaign.

4

Explain the fundamentals and major stages of a malware forensic investigation.

5

Distinguish between static, dynamic, and hybrid malware analysis.

6

Describe a systematic workflow for the static analysis of a suspicious executable file.

7

Explain how hashes, strings, imports, file headers, and entropy assist in static malware analysis.

8

What are malware packing and obfuscation? Explain how they affect static analysis and how an analyst can identify them.

9

Describe how a suspicious Microsoft Word document can be analyzed for malicious content.

10

Explain the important objects and indicators that should be examined when analyzing a suspicious PDF document.

11

Compare the forensic analysis of suspicious Word and PDF documents.

12

Explain the fundamentals of dynamic malware analysis and describe the requirements of a safe analysis laboratory.

13

Compare automated sandboxing, manual behavioral analysis, and debugger-assisted malware analysis.

14

Describe how malware behavior affecting system properties can be analyzed in real time.

15

Explain how real-time analysis can reveal malware persistence, privilege escalation, and process injection.

16

Describe the procedure for analyzing malware network behavior in real time.

17

What network indicators may suggest command-and-control communication or data exfiltration by malware?

18

Explain how host and network evidence can be correlated to reconstruct a malware incident timeline.

19

Explain common anti-analysis techniques used by malware and describe how analysts can respond to them.

20

Define fileless malware and explain, with a typical attack chain, how a fileless malware attack happens.