CS0-003 Incident Response and Management Practice Question
A security analyst is performing static analysis on a suspicious PE file. Which initial step should the analyst take to understand the file's imports and potential capabilities?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze the PE header and import table.
Analyzing the import table reveals which Windows API functions the file uses, providing insight into its functionality (e.g., network, file, or registry operations).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a YARA rule based on hash characteristics.
Why it's wrong here
Creating a YARA rule is a signature-based detection mechanism used to scan filesystems or memory for known malware patterns, rather than an analytical technique to understand an unknown binary's capabilities. Furthermore, writing a rule based solely on a file hash is redundant and inefficient, as simple hash matching is better handled by traditional threat intelligence lookups or basic blocklists.
- ✗
Run the file in a sandbox and observe behavior.
Why it's wrong here
Executing the suspicious file within an isolated sandbox environment allows analysts to monitor its runtime behavior, process creation, and network connections. However, this approach constitutes dynamic analysis, which violates the scenario's constraint of performing static analysis where the code is examined without actually executing it.
- ✗
Extract strings from the file.
Why it's wrong here
Extracting ASCII and Unicode strings can reveal embedded IP addresses, URLs, or error messages, but it lacks the structural context needed to map API dependencies. This method often produces a cluttered, unorganized list of text that does not reliably identify the specific Windows APIs or DLLs the binary imports to execute its payload.
- ✓
Analyze the PE header and import table.
Why this is correct
Examining the Portable Executable (PE) header and its Import Address Table (IAT) is a fundamental static analysis technique that reveals the specific dynamic-link libraries (DLLs) and functions the executable requests from the operating system. This structural analysis allows the analyst to infer the program's intended capabilities, such as network communication or registry modification, without executing the code.
Go deeper
Related to this question
Learn chapter
Splunk SPL Queries for Security Analysts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.