exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 686 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 686
Topic #: 1
[All 312-49v10 Questions]

An experienced forensic investigator, Chris, is tasked with preparing a testbed for malware analysis. Given the complexity of the malware samples, which are mostly compatible with Windows binary executables, Chris must take meticulous precautions to ensure the integrity of the lab environment. Which of the following procedures would Chris NOT be likely to follow in preparing the testbed for malware analysis?

  • A. Installing a guest OS such as Ubuntu in virtual machines will serve as forensic workstations
  • B. Enabling shared folders and guest isolation allows easy data transfer between host and guest operating systems
  • C. Using tools such as INetSim to simulate internet services while ensuring that the NIC card is in "host only" mode
  • D. Creating a snapshot of the virtual machine state prior to malware analysis for easy reversion in case of accidental system corruption
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
044f354
5 days, 12 hours ago
Selected Answer: B
Answer: B Enabling shared folders increases risk of malware escaping the sandbox. (A) ✅ Ubuntu can be used as a secure forensic analysis host. (B) ❌ Shared folders/guest isolation compromise containment, violating malware lab isolation best practices. (C) ✅ INetSim with host-only NIC safely simulates network services without exposing to the internet. (D) ✅ VM snapshots are standard practice to restore clean environments after analysis. ----- If you agree: UPVOTE this post to add your vote to the community tally. If you disagree: discuss with citations Both actions crowdsource best answers.
upvoted 1 times
...
aqeel1506
8 months, 2 weeks ago
A. Installing a guest OS such as Ubuntu in virtual machines will serve as forensic workstations The textbook emphasizes the use of Windows-based virtual machines for analyzing Windows malware to ensure compatibility and proper analysis. Installing a Linux-based OS like Ubuntu would not be appropriate for analyzing Windows binary executables. The other procedures mentioned—using shared folders with guest isolation, using simulation tools, and creating snapshots—are in line with best practices for preparing a malware analysis testbed.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago