Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

A security analyst is reviewing a malware sample in a sandbox environment. The analyst notes that the malware attempts to check for the presence of a debugger and modifies its behavior if one is detected. Additionally, the malware uses encrypted strings and resolves API calls dynamically. Which THREE analysis techniques would be most effective for understanding this malware's capabilities? (Select THREE.)

⚠ Common exam trap

CAS-005 often tests the misconception that simple hash or network analysis is sufficient for evasive malware, when in fact obfuscated and anti-debugging malware requires deeper static, dynamic, and memory analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Static analysis using a disassembler like IDA Pro to examine the code for anti-debugging and obfuscation techniques

Option A is correct because static analysis with a disassembler such as IDA Pro lets the analyst inspect the binary's code directly, revealing the anti-debugging checks (e.g., IsDebuggerPresent, PEB BeingDebugged flag) and the obfuscation/encrypted-string routines without executing the sample. Option D is correct because dynamic analysis in a sandbox observes the malware's actual runtime behavior, and since the sample alters its behavior when a debugger is detected, running it in an instrumented sandbox (without an attached debugger) exposes the alternate execution path and its true capabilities. Option E is correct because memory analysis with Volatility captures the malware's process memory, allowing recovery of dynamically resolved API addresses, decrypted strings, and unpacked code that never appear on disk. Option B is not among the correct answers because Wireshark packet capture only shows network traffic and cannot reveal the anti-debugging logic, encrypted strings, or dynamic API resolution central to this sample. Option C is not among the correct answers because VirusTotal hash lookups only provide reputation and prior detection data, not an understanding of the malware's internal capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Static analysis using a disassembler like IDA Pro to examine the code for anti-debugging and obfuscation techniques

    Why this is correct

    Disassembly with IDA Pro reveals anti-debugging checks, encrypted string routines and dynamic API resolution logic in the code itself, without executing the sample. This exposes the obfuscation and evasion mechanisms the malware uses, which behavioural observation alone cannot fully map.

  • ✗

    Network analysis using Wireshark to capture packets from the sandbox

    Why it's wrong here

    Wireshark captures sandbox traffic, exposing command-and-control and exfiltration, yet it cannot decode the sample's encrypted strings or dynamic API resolution inside the process. It is tempting because network analysis is standard sandbox practise, but it suits identifying external communications rather than internal evasive logic.

  • ✗

    Hash analysis by submitting the malware to VirusTotal

    Why it's wrong here

    VirusTotal returns reputation and hash matches from prior submissions; it cannot reveal this sample's debugger checks, encrypted strings or dynamic API resolution. It is tempting as rapid triage to identify known malware, but that fits confirming a sample's identity, not understanding evasive runtime behaviour.

  • ✓

    Dynamic analysis in a sandbox to observe the malware's behavior after it detects a debugger

    Why this is correct

    Sandbox execution observes the malware's actual behaviour, including the alternate path it takes once a debugger is detected, plus network calls and dropped artefacts. This reveals capabilities hidden behind anti-debugging checks that static inspection cannot resolve.

  • ✓

    Memory analysis using Volatility on the sandbox host to capture the malware's process memory

    Why this is correct

    Volatility parses the captured memory image to recover decrypted strings, injected code and dynamically resolved API addresses held only at runtime. This defeats the encrypted strings and dynamic resolution that obscure static analysis, exposing the malware's true capabilities.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.