CySA+ Test Malware Analysis Flashcards
6 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CySA+ Test Malware Analysis flashcards as text
Which malware analysis technique executes a sample in an isolated environment to observe its behavior without risking production systems?
Answer: Dynamic analysis
Dynamic analysis runs malware in a sandbox to observe runtime behavior such as file writes, network calls, and registry changes.
A CySA+ analyst uses a disassembler to examine malware without executing it. This is an example of which analysis type?
Answer: Static analysis
Static analysis inspects malware code, strings, and structure without running it, often using tools like disassemblers and hex editors.
Which indicator would BEST suggest a piece of malware is performing process injection?
Answer: Unexpected DLL loaded in a legitimate process memory space
Process injection is characterized by a foreign DLL or code being loaded into a legitimate process's memory space to evade detection.
Which type of malware is specifically designed to record keystrokes and transmit them to an attacker?
Answer: Keylogger
A keylogger captures and logs keyboard input, often to steal credentials or sensitive information.
An analyst identifies malware that modifies the Master Boot Record (MBR). Which malware classification BEST fits this behavior?
Answer: Bootkit
A bootkit infects the MBR or boot sector, loading before the OS and persisting across reboots.
Which tool is commonly used during static malware analysis to extract human-readable text embedded in a binary?
Answer: strings utility
The strings utility extracts printable character sequences from binary files, often revealing URLs, registry keys, or commands.