CCE Incident Response & Malware Analysis Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CCE Incident Response & Malware Analysis flashcards as text
In incident response triage, what does the order of volatility principle dictate about evidence collection?
Answer: Collect the most volatile data (RAM, running processes) first before it is lost
The order of volatility requires collecting the most transient data first—RAM, running processes, network connections—before powering down a system, as this data is lost on shutdown.
What is a 'chain of custody' and why is it critical during incident response investigations in the US?
Answer: A documented record tracking who handled evidence, when, and what was done to it, ensuring admissibility in US courts
Chain of custody documentation ensures evidence integrity and tracks every person who accessed the evidence, which is required for the evidence to be admissible in US legal proceedings.
Which Windows artifact records the execution history of programs and is examined during incident response to identify malware execution?
Answer: Prefetch files (C:\Windows\Prefetch\)
Windows Prefetch files record metadata about program execution, including the executable name, run count, and last run time, helping investigators confirm whether malware was executed.
During malware analysis, what is the significance of an executable importing 'VirtualAlloc' and 'WriteProcessMemory' from the Windows API?
Answer: These functions are commonly used for process injection and shellcode execution in malicious software
VirtualAlloc allocates memory and WriteProcessMemory writes data into another process's memory space; together they are hallmarks of code injection techniques used by malware.
In the context of ransomware incident response, what is the recommended first action upon discovering an active ransomware infection on a networked machine?
Answer: Isolate the infected system from the network to prevent lateral movement and further encryption
Immediate network isolation (unplugging the network cable or disabling the NIC) stops ransomware from spreading to other systems while preserving the local system for forensic analysis.
What is lateral movement in the context of an incident response investigation?
Answer: Techniques used by attackers to progressively move through a network after initial compromise to reach target systems
Lateral movement refers to attacker techniques such as pass-the-hash, RDP exploitation, or credential theft used to pivot from an initially compromised system to other valuable targets on the same network.