CAS-004 Security Operations Practice Question
A security analyst is investigating a malware sample found on a workstation. The analyst wants to determine the malware's capabilities without executing it. Which type of malware analysis involves examining the binary's strings, headers, and structure?
⚠ Common exam trap
A common mix-up: candidates confuse static analysis with reverse engineering; while reverse engineering is a subset of static analysis, the question specifically asks about examining strings and headers, which is classic static analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static analysis
Static analysis involves examining the malware binary without executing it, focusing on its structure, strings, headers, and other static properties. This allows the analyst to extract indicators like embedded URLs, IP addresses, and function calls without risking infection or triggering malicious behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Static analysis
Why this is correct
Static analysis examines the binary's strings, headers and structure without running it, directly satisfying the stem's constraint of determining capabilities without execution. Dynamic or behavioural analysis would require detonating the sample in a sandbox, which the analyst explicitly wants to avoid.
- ✗
Dynamic analysis
Why it's wrong here
Dynamic analysis executes the sample in a sandbox or VM to observe behaviour, directly contradicting the requirement to avoid execution. It is tempting because it yields rich capability data, and would be correct when safe detonation is permitted and runtime actions such as network callbacks must be captured.
- ✗
Reverse engineering
Why it's wrong here
Reverse engineering disassembles code to reconstruct logic, exceeding the static examination of strings, headers and structure the question describes. It is tempting because it also avoids execution, and would be correct when the analyst needs to understand obfuscated routines or algorithm behaviour beyond surface metadata.
- ✗
Memory forensics
Why it's wrong here
Memory forensics analyses volatile RAM from a running or captured system, not an on-disk binary's strings and headers. It is tempting because it is also non-executing and reveals runtime artefacts, and would be correct when investigating injected processes or unpacked code resident in memory.
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.