EC-Council certification practice
112-57 Practice Questions
Try 10 free 112-57 exam-style questions for Threat Intelligence Essentials. Check each answer and review the explanation and source references.
- Exam code
- 112-57
- Provider
- EC-Council
- Free questions
- 10
- Full set
- 75 questions
- Last update check
Cheryl, a forensic expert, was recruited to investigate a malicious activity performed by an
anonymous hackers’ group on an organization’s systems. Using an automated tool, Cheryl was able
to extract the malware file and analyze the assembly code instructions, which helped him understand
the malware’s purpose.
Which of the following tools helped Cheryl extract and analyze the assembly code of the malware?
Which of the following types of phishing attacks allows an attacker to exploit instant messaging
platforms by employing IM as a tool to spread spam?
Given below are different steps involved in event correlation.
Event masking
Event aggregation
Root cause analysis
Event filtering
Identify the correct sequence of steps involved in event correlation.
Sandra, a hacker, targeted Johana, a software professional, to steal her banking details. She started
sending frequent, random pop-up messages with malicious links to her social media page. Johana
accidentally clicked on a link, causing a malicious program to get installed in her system.
Subsequently, when Johana attempted to access her banking website, the URL redirected her to a
malicious website controlled by Sandra. Johana entered her banking credentials on the fake website,
which Sandra then captured.
Identify the type of attack performed by Sandra on Johana.
Identify the malware analysis technique in which the investigators must take a snapshot of the
baseline state of the forensic workstation before malware execution.
Given below is a regex signature used by security professionals for detecting an XSS attack:
/((%3C)|)/i
Which of the following types of XSS attack does the above regex expression detect?
Which of the following folders of macOS stores all the files, documents, applications, library folders,
etc. pertaining to a particular user?
An investigator wants to extract information about the status of the network interface cards (NICs) in
an organization’s Windows-based systems. Identify the command-line utility that can help the
investigator detect the network status.
Williams, a forensic specialist, was tasked with performing a static malware analysis on a suspect
system in an organization. For this purpose, Williams used an automated tool to perform a string
search and saved all the identified strings in a text file. After analyzing the strings, he determined all
the harmful actions that were performed by malware.
Identify the tool employed by Williams in the above scenario.
An organization decided to strengthen the security of its network by studying and analyzing the
behavior of attackers. For this purpose, Steven, a security analyst, was instructed to deploy a device
to bait attackers. Steven selected a solution that appears to contain very useful information to lure
attackers and find their locations and techniques.
Identify the type of device deployed by Steven in the above scenario.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
