CAS-004 Security Operations Practice Question
A security operations center (SOC) analyst is investigating a potential malware infection on a workstation. The analyst wants to perform static analysis on a suspicious executable. Which tool or technique is most appropriate for examining the executable without executing it?
⚠ Common exam trap
CAS-005 often tests the distinction between static and dynamic analysis, and candidates may choose sandboxing (dynamic) when asked for a non-execution method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the strings command to extract readable ASCII and Unicode strings
Static analysis involves examining an executable without running it. The strings command extracts readable ASCII and Unicode strings from a binary, which can reveal URLs, IP addresses, error messages, and other indicators without executing the code. This is a safe and quick method for initial triage of suspicious files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run the executable in a sandbox
Why it's wrong here
Sandbox execution runs the sample and observes its behaviour, which is dynamic analysis, directly contradicting the requirement to examine it without executing. It is tempting because sandboxing is the standard triage step, and would be correct when behavioural indicators or C2 callbacks are needed, but static analysis instead inspects headers, strings and imports.
- ✗
Use a memory forensics tool like Volatility
Why it's wrong here
Volatility parses RAM captures, so it examines volatile memory of a running or recently running system rather than the executable file on disk. It is tempting because memory artefacts reveal injected code and process hollowing, and would be correct for live-response triage, but the stem asks for file-level inspection without execution.
- ✓
Use the strings command to extract readable ASCII and Unicode strings
Why this is correct
The strings command extracts readable ASCII and Unicode sequences from a binary without executing it, revealing URLs, file paths and messages. This satisfies the stem's static analysis constraint, unlike dynamic tools that run the executable in a sandbox.
- ✗
Perform a network traffic capture
Why it's wrong here
A network capture records packets in transit, revealing command-and-control or exfiltration traffic, not the binary's internal structure. It is tempting because traffic analysis is central to malware investigations, and would be correct for identifying beaconing or payload delivery, but static analysis requires reading the file's code and metadata offline.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.