CS0-003 Incident Response and Management Practice Question
A security analyst is analyzing a suspicious file using static analysis. The analyst wants to identify imported functions to determine the file's capabilities. Which tool or technique is BEST suited for this task?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyzing the PE header's import table
PE header analysis includes examining the import table to see which Windows API functions the executable calls, revealing its potential behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Extracting strings from the file
Why it's wrong here
Extracting strings from a binary can reveal hardcoded IP addresses, URLs, and error messages, but it does not provide a structured, reliable view of the APIs the file imports. Packed or obfuscated binaries will hide these strings entirely, making this method insufficient for mapping out the exact system functions and DLL dependencies the executable relies on for its core operations.
- ✗
Submitting the file to VirusTotal
Why it's wrong here
Submitting a file to VirusTotal is a quick way to check for known signatures and aggregate threat intelligence from dozens of antivirus engines. However, this action does not constitute a hands-on static analysis of the file's structure, nor does it directly expose the specific imported functions or API calls of an unknown or custom malware sample.
- ✗
Running the file in a sandbox like Cuckoo
Why it's wrong here
Utilizing an automated sandbox like Cuckoo Sandbox represents dynamic analysis, which involves executing the malware in a controlled environment to observe its runtime behavior, registry modifications, and network traffic. This is fundamentally different from static analysis, which examines the file's code and structure without actually executing it, thereby avoiding the risk of sandbox evasion techniques.
- ✓
Analyzing the PE header's import table
Why this is correct
Analyzing the Portable Executable (PE) header's import table, specifically the Import Address Table (IAT), is a fundamental static analysis technique. It explicitly lists the dynamic-link libraries (DLLs) and the specific functions that the binary requests from the operating system, such as InternetOpenA or WriteProcessMemory. This provides immediate, concrete clues about the program's intended capabilities and behavior without executing the payload.
Go deeper
Related to this question
Learn chapter
Security Architecture Review for Analysts
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.