Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security operations center (SOC) analyst is investigating a potential malware infection on a workstation. The analyst wants to perform static analysis on a suspicious executable. Which tool or technique is most appropriate for examining the executable without executing it?

⚠ Common exam trap

CAS-005 often tests the distinction between static and dynamic analysis, and candidates may choose sandboxing (dynamic) when asked for a non-execution method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the strings command to extract readable ASCII and Unicode strings

Static analysis involves examining an executable without running it. The strings command extracts readable ASCII and Unicode strings from a binary, which can reveal URLs, IP addresses, error messages, and other indicators without executing the code. This is a safe and quick method for initial triage of suspicious files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run the executable in a sandbox

    Why it's wrong here

    Sandbox execution runs the sample and observes its behaviour, which is dynamic analysis, directly contradicting the requirement to examine it without executing. It is tempting because sandboxing is the standard triage step, and would be correct when behavioural indicators or C2 callbacks are needed, but static analysis instead inspects headers, strings and imports.

  • ✗

    Use a memory forensics tool like Volatility

    Why it's wrong here

    Volatility parses RAM captures, so it examines volatile memory of a running or recently running system rather than the executable file on disk. It is tempting because memory artefacts reveal injected code and process hollowing, and would be correct for live-response triage, but the stem asks for file-level inspection without execution.

  • ✓

    Use the strings command to extract readable ASCII and Unicode strings

    Why this is correct

    The strings command extracts readable ASCII and Unicode sequences from a binary without executing it, revealing URLs, file paths and messages. This satisfies the stem's static analysis constraint, unlike dynamic tools that run the executable in a sandbox.

  • ✗

    Perform a network traffic capture

    Why it's wrong here

    A network capture records packets in transit, revealing command-and-control or exfiltration traffic, not the binary's internal structure. It is tempting because traffic analysis is central to malware investigations, and would be correct for identifying beaconing or payload delivery, but static analysis requires reading the file's code and metadata offline.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.