CCE Incident Response & Malware Analysis Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCE Incident Response & Malware Analysis flashcards as text
During memory forensics, which Volatility plugin would a CCE examiner use to list running processes from a memory dump?
Answer: pslist or pstree
The 'pslist' and 'pstree' plugins in Volatility enumerate running processes from a memory image, revealing active and potentially malicious processes.
What is process hollowing, and why is it significant in malware analysis?
Answer: Injecting malicious code into a legitimate process's memory space by replacing its contents; used to evade detection
Process hollowing involves starting a legitimate process, unmapping its code from memory, and replacing it with malicious code to evade security tools that whitelist trusted processes.
Which Windows registry hive contains autorun entries most commonly abused by malware for persistence?
Answer: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
The 'Run' and 'RunOnce' keys under HKCU and HKLM \Software\Microsoft\Windows\CurrentVersion are the most common registry locations malware uses to establish persistence.
What is a 'rootkit' and how does it complicate digital forensic investigations?
Answer: Malware that hides its presence by modifying OS structures to conceal files, processes, and network connections
Rootkits subvert OS functions to hide malicious activity, making standard tools return false information and requiring offline analysis or specialized tools to detect.
During an incident response investigation, an examiner finds a PowerShell script with base64-encoded content. What is the most appropriate first step?
Answer: Decode the base64 content in an isolated environment to determine its purpose
Base64 encoding in PowerShell is a common obfuscation technique; decoding it in an isolated environment reveals the actual commands being executed without risk.
What is the primary purpose of a YARA rule in malware analysis and incident response?
Answer: Pattern matching to identify and classify malware based on textual or binary patterns
YARA rules define patterns (strings, byte sequences, conditions) used to scan files and memory to identify and classify malware families across large datasets.