312-49 Exam QuestionsBrowse all questions from this exam

312-49 Exam - Question 141


Chong-lee, a forensics executive, suspects that a malware is continuously making copies of files and folders on a victim system to consume the available disk space. What type of test would confirm his claim?

Show Answer
Correct Answer: D

Dynamic analysis involves observing the system in real-time to monitor its behavior and interactions, which includes detecting any continuous file and folder copying by malware to consume disk space. This would allow Chong-lee to confirm his suspicion by examining the active file operations and changes occurring within the system.

Discussion

3 comments
Sign in to comment
FabsauroOption: D
Apr 17, 2021

Why note Dynamic analysis ? We could view the mentioned copies.

MrRubiOption: D
Jul 27, 2022

It is 100% possible with dynamic analysis. I would go with D

db902ecOption: D
Jun 2, 2024

File fingerprinting when Chong-lee doesn't know the file seems incorrect. Dynamic Analysis to find live file duplication would be the correct answer