CAS-004 Security Operations Practice Question
During a malware analysis, an analyst runs a suspicious binary in a sandbox and observes that it attempts to communicate with a known malicious IP address, modifies registry keys, and creates a service. The analyst then extracts strings from the binary and finds references to a specific C2 server. Which analysis phase does the extraction of strings represent?
⚠ Common exam trap
The trap is mixing up static and dynamic analysis phases; candidates might think that because the malware was run in a sandbox, all subsequent analysis is dynamic, but string extraction is purely static.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static analysis
Extracting strings from a binary is a static analysis technique because it examines the file's contents without executing it. The strings command or similar tools reveal embedded text such as URLs, IP addresses, and error messages, which can provide immediate indicators of compromise like the C2 server address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dynamic analysis
Why it's wrong here
Running the binary and observing its network, registry and service behaviour is dynamic analysis; extracting strings reads static bytes without execution, so it belongs to static analysis. Dynamic analysis is tempting because sandbox execution genuinely reveals runtime indicators, and would be correct had the question asked how the C2 communication was observed.
- ✗
Reverse engineering
Why it's wrong here
Extracting printable strings is a static, automated triage step requiring no disassembly or code comprehension, so it does not constitute reverse engineering. Reverse engineering is tempting because it also examines the binary without running it, and would be correct had the analyst disassembled the code to trace the C2 logic.
- ✓
Static analysis
Why this is correct
Extracting strings examines the binary's raw bytes without executing it, revealing embedded artefacts such as the C2 server address. That places it firmly in static analysis, which inspects code and metadata at rest, distinct from the dynamic sandbox observation already performed.
- ✗
Memory analysis
Why it's wrong here
Strings are pulled directly from the on-disk binary, not from a captured RAM image, so no volatile memory artefacts are examined. Memory analysis is tempting because it recovers injected code, decrypted strings and running processes, and would be correct had the analyst dumped the sandbox VM's memory.
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.