ExamQuestions.com

Register
Login
CompTIA CySA+ Certification Exam (CS0-002) Exam Questions

CompTIA

CompTIA CySA+ Certification Exam (CS0-002)

151 / 160

Question 151:

During an incident investigation, a security analyst acquired a malicious file that was used as a backdoor but was not detected by the antivirus application. After performing a reverse-engineering procedure, the analyst found that part of the code was obfuscated to avoid signature detection. Which of the following types of instructions should the analyst use to understand how the malware was obfuscated and to help deobfuscate it? 

Answer options:

A. MOV
B. ADD
C. XOR
D. SUB
E. MOVL