CAS-004 Security Operations Practice Question
A security analyst is investigating a malware sample and wants to determine its capabilities without executing it. The analyst examines the binary's imports, strings, and structure. What type of analysis is being performed?
⚠ Common exam trap
Many candidates confuse static analysis with reverse engineering, as both involve examining code without execution, but reverse engineering is a broader process that includes static and dynamic methods; the question specifically describes non-execution inspection of imports, strings, and structure, which is static analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static analysis
Static analysis involves examining a file's code, structure, and metadata without running it. By inspecting imports, strings, and headers, the analyst gains insight into potential functionality (e.g., API calls, embedded URLs) without risking execution. This is the definition of static analysis, as opposed to dynamic analysis which requires running the sample. Reverse engineering is a broader process that includes static and dynamic techniques, but the specific actions described are classic static analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Memory analysis
Why it's wrong here
Memory analysis inspects RAM captures or process memory dumps from a running or compromised host, requiring the sample or system to have executed. It is tempting because it exposes artefacts invisible on disk, and would be correct when examining volatile data from an infected machine rather than inspecting a dormant binary file.
- ✓
Static analysis
Why this is correct
Static analysis examines a binary's code, imports, strings and structure without running it, directly satisfying the stem's constraint of determining capabilities without execution. Unlike dynamic analysis, which observes runtime behaviour in a sandbox, static analysis reveals potential functionality through inspection alone, making it the appropriate technique here.
- ✗
Reverse engineering
Why it's wrong here
Reverse engineering reconstructs code or logic, typically through disassembly or decompilation, to recover algorithms and control flow. It is tempting because it also avoids execution, and would be correct when the analyst needs to understand the malware's internal implementation rather than just its imports, strings and structure.
- ✗
Dynamic analysis
Why it's wrong here
Dynamic analysis observes behaviour while the sample runs in a sandbox or virtual machine, capturing network traffic, file and registry changes. It is tempting because it reveals capabilities that static inspection can miss, and would be correct when the analyst executes the malware in an isolated environment to record its runtime actions.
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.