Courseiva
Security Operations →hardMultiple Choice

CAS-004 Security Operations Practice Question

During a malware analysis, an analyst runs a suspicious binary in a sandbox and observes that it attempts to communicate with a known malicious IP address, modifies registry keys, and creates a service. The analyst then extracts strings from the binary and finds references to a specific C2 server. Which analysis phase does the extraction of strings represent?

⚠ Common exam trap

The trap is mixing up static and dynamic analysis phases; candidates might think that because the malware was run in a sandbox, all subsequent analysis is dynamic, but string extraction is purely static.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Static analysis

Extracting strings from a binary is a static analysis technique because it examines the file's contents without executing it. The strings command or similar tools reveal embedded text such as URLs, IP addresses, and error messages, which can provide immediate indicators of compromise like the C2 server address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dynamic analysis

    Why it's wrong here

    Running the binary and observing its network, registry and service behaviour is dynamic analysis; extracting strings reads static bytes without execution, so it belongs to static analysis. Dynamic analysis is tempting because sandbox execution genuinely reveals runtime indicators, and would be correct had the question asked how the C2 communication was observed.

  • ✗

    Reverse engineering

    Why it's wrong here

    Extracting printable strings is a static, automated triage step requiring no disassembly or code comprehension, so it does not constitute reverse engineering. Reverse engineering is tempting because it also examines the binary without running it, and would be correct had the analyst disassembled the code to trace the C2 logic.

  • ✓

    Static analysis

    Why this is correct

    Extracting strings examines the binary's raw bytes without executing it, revealing embedded artefacts such as the C2 server address. That places it firmly in static analysis, which inspects code and metadata at rest, distinct from the dynamic sandbox observation already performed.

  • ✗

    Memory analysis

    Why it's wrong here

    Strings are pulled directly from the on-disk binary, not from a captured RAM image, so no volatile memory artefacts are examined. Memory analysis is tempting because it recovers injected code, decrypted strings and running processes, and would be correct had the analyst dumped the sandbox VM's memory.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.