CCE Incident Response & Malware Analysis Flashcards
6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCE Incident Response & Malware Analysis flashcards as text
According to NIST SP 800-61, what are the four phases of the incident response lifecycle?
Answer: Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity
NIST SP 800-61 defines the incident response lifecycle as Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.
During malware analysis, what is the difference between static and dynamic analysis?
Answer: Static analysis examines the malware without executing it; dynamic analysis runs the malware in a controlled environment
Static analysis inspects malware code, strings, and structure without execution, while dynamic analysis runs the malware in a sandbox to observe its behavior.
What is a 'sandbox' in the context of malware analysis?
Answer: An isolated virtual environment used to execute and observe malware behavior safely
A sandbox is an isolated environment (typically a VM) where malware can be executed and monitored without risk of infecting production systems.
In incident response, what does the term 'containment' refer to?
Answer: Limiting the spread and impact of an incident while preserving forensic evidence
Containment involves taking steps to stop the incident from spreading further while carefully preserving evidence for forensic analysis.
What tool would a CCE examiner use to examine strings embedded in a malware binary without executing it?
Answer: The 'strings' utility or BinText
The 'strings' command-line utility or tools like BinText extract printable character sequences from a binary, often revealing URLs, registry keys, and function names.
What is 'indicators of compromise' (IOCs) and how are they used in incident response?
Answer: Observable artifacts (IP addresses, file hashes, registry keys) that indicate a system may be compromised
IOCs are forensic artifacts such as malicious IP addresses, file hashes, registry entries, or domain names used to identify compromised systems and detect similar attacks.