EC-Council certification practice

112-57 Practice Questions

Try 10 free 112-57 exam-style questions for Threat Intelligence Essentials. Check each answer and review the explanation and source references.

Exam code
112-57
Provider
EC-Council
Free questions
10
Full set
75 questions
Last update check
Cheryl, a forensic expert, was recruited to investigate a malicious activity performed by an anonymous hackers’ group on an organization’s systems. Using an automated tool, Cheryl was able to extract the malware file and analyze the assembly code instructions, which helped him understand the malware’s purpose. Which of the following tools helped Cheryl extract and analyze the assembly code of the malware?
Answer options
Which of the following types of phishing attacks allows an attacker to exploit instant messaging platforms by employing IM as a tool to spread spam?
Answer options
Given below are different steps involved in event correlation. Event masking Event aggregation Root cause analysis Event filtering Identify the correct sequence of steps involved in event correlation.
Answer options
Sandra, a hacker, targeted Johana, a software professional, to steal her banking details. She started sending frequent, random pop-up messages with malicious links to her social media page. Johana accidentally clicked on a link, causing a malicious program to get installed in her system. Subsequently, when Johana attempted to access her banking website, the URL redirected her to a malicious website controlled by Sandra. Johana entered her banking credentials on the fake website, which Sandra then captured. Identify the type of attack performed by Sandra on Johana.
Answer options
Identify the malware analysis technique in which the investigators must take a snapshot of the baseline state of the forensic workstation before malware execution.
Answer options
Given below is a regex signature used by security professionals for detecting an XSS attack: /((%3C)|)/i Which of the following types of XSS attack does the above regex expression detect?
Answer options
Which of the following folders of macOS stores all the files, documents, applications, library folders, etc. pertaining to a particular user?
Answer options
An investigator wants to extract information about the status of the network interface cards (NICs) in an organization’s Windows-based systems. Identify the command-line utility that can help the investigator detect the network status.
Answer options
Williams, a forensic specialist, was tasked with performing a static malware analysis on a suspect system in an organization. For this purpose, Williams used an automated tool to perform a string search and saved all the identified strings in a text file. After analyzing the strings, he determined all the harmful actions that were performed by malware. Identify the tool employed by Williams in the above scenario.
Answer options
An organization decided to strengthen the security of its network by studying and analyzing the behavior of attackers. For this purpose, Steven, a security analyst, was instructed to deploy a device to bait attackers. Steven selected a solution that appears to contain very useful information to lure attackers and find their locations and techniques. Identify the type of device deployed by Steven in the above scenario.
Answer options
Question 1 of 10

Source context

How this practice set is maintained

Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.

Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.

Scroll to Top