← All CCE Flashcard Decks

CCE Incident Response & Malware Analysis Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CCE Incident Response & Malware Analysis flashcards as text
  1. In incident response triage, what does the order of volatility principle dictate about evidence collection?

    Answer: Collect the most volatile data (RAM, running processes) first before it is lost

    The order of volatility requires collecting the most transient data first—RAM, running processes, network connections—before powering down a system, as this data is lost on shutdown.

  2. What is a 'chain of custody' and why is it critical during incident response investigations in the US?

    Answer: A documented record tracking who handled evidence, when, and what was done to it, ensuring admissibility in US courts

    Chain of custody documentation ensures evidence integrity and tracks every person who accessed the evidence, which is required for the evidence to be admissible in US legal proceedings.

  3. Which Windows artifact records the execution history of programs and is examined during incident response to identify malware execution?

    Answer: Prefetch files (C:\Windows\Prefetch\)

    Windows Prefetch files record metadata about program execution, including the executable name, run count, and last run time, helping investigators confirm whether malware was executed.

  4. During malware analysis, what is the significance of an executable importing 'VirtualAlloc' and 'WriteProcessMemory' from the Windows API?

    Answer: These functions are commonly used for process injection and shellcode execution in malicious software

    VirtualAlloc allocates memory and WriteProcessMemory writes data into another process's memory space; together they are hallmarks of code injection techniques used by malware.

  5. In the context of ransomware incident response, what is the recommended first action upon discovering an active ransomware infection on a networked machine?

    Answer: Isolate the infected system from the network to prevent lateral movement and further encryption

    Immediate network isolation (unplugging the network cable or disabling the NIC) stops ransomware from spreading to other systems while preserving the local system for forensic analysis.

  6. What is lateral movement in the context of an incident response investigation?

    Answer: Techniques used by attackers to progressively move through a network after initial compromise to reach target systems

    Lateral movement refers to attacker techniques such as pass-the-hash, RDP exploitation, or credential theft used to pivot from an initially compromised system to other valuable targets on the same network.