nerdexam
EC-Council

312-49V11 · Question #112

During a malware analysis investigation, a suspicious Microsoft Office document is identified as a potential threat. The document contains embedded macros and triggers unusual behavior when opened…

The correct answer is C. To identify potential malware or malicious code embedded within the document. According to the CHFI v11 objectives under Malware Forensics and Static and Dynamic Malware Analysis, Microsoft Office documents are one of the most common delivery mechanisms for malware, especially through malicious macros, embedded scripts, and exploit-laden objects…

Malware Forensics

Question

During a malware analysis investigation, a suspicious Microsoft Office document is identified as a potential threat. The document contains embedded macros and triggers unusual behavior when opened. In digital forensics, what is the primary purpose of analyzing suspicious Microsoft Office documents?

Options

  • ATo determine the author's identity
  • BTo optimize the formatting and layout of the document
  • CTo identify potential malware or malicious code embedded within the document
  • DTo improve the performance of Microsoft Office applications

How the community answered

(21 responses)
  • B
    5% (1)
  • C
    86% (18)
  • D
    10% (2)

Explanation

According to the CHFI v11 objectives under Malware Forensics and Static and Dynamic Malware Analysis, Microsoft Office documents are one of the most common delivery mechanisms for malware, especially through malicious macros, embedded scripts, and exploit-laden objects. Attackers frequently weaponize Word, Excel, and PowerPoint files to execute malicious code when a user opens the document or enables macros. The primary forensic purpose of analyzing suspicious Microsoft Office documents is to identify embedded malware or malicious code and understand how it executes. Investigators examine macro code (VBA), embedded objects, OLE streams, and document metadata to detect indicators such as obfuscated scripts, PowerShell execution commands, shellcode loaders, or downloader functionality. CHFI v11 emphasizes that this analysis helps determine the infection chain, execution triggers, and potential impact on the compromised system.

Topics

#Office document forensics#macro analysis#embedded malware#document forensics

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice