exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 748 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 748
Topic #: 1
[All 312-49v10 Questions]

As part of an ongoing investigation, a CHFI is tasked with identifying and analyzing stealthy malware that has caused severe damage to a major corporation's systems. The malware has left minimal traces, demonstrating its sophisticated nature. It's also believed that the malware originated from the dark web. Based on the available information, what should be the investigator's priority in the malware forensic process?

  • A. Immediately searching the dark web for similar malware signatures
  • B. Creating a list of IoCs from other machines in the network to check for malware presence
  • C. Setting up a controlled malware analysis lab to study the behavior of the malware
  • D. Sending a copy of the malware to anti-virus companies for urgent signature development
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
044f354
3 days, 14 hours ago
Selected Answer: C
ECCouncil Official CHFI https://bookshelf.vitalsource.com/reader/books/9781635676969/ Module 14 Page 1299 - Usually, malware analysis is carried out by infecting a system with a malicious code and then evaluating its behavior using a set of monitoring tools. Therefore, a dedicated laboratory system is required that can be infected while keeping the production environment safe. - If you agree: UPVOTE this post to add your vote to the community tally. If you disagree: discuss with citations Both actions crowdsource best answers.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago