Courseiva
mediumMultiple Select

CS0-003 Practice Question: A security analyst is reviewing a suspicious…

A security analyst is reviewing a suspicious email attachment. Which THREE of the following are safe analysis techniques? (Choose THREE)

⚠ Common exam trap

The CS0-004 exam often tests the distinction between 'safe' and 'unsafe' analysis techniques, where candidates mistakenly think examining source code (Option C) is always safe, but it can still trigger execution if the file is opened in an unsecured environment (e.g., enabling macros in Office documents).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit the file to a public online scanner

Submitting a suspicious file to a public online scanner (e.g., VirusTotal) allows the analyst to check the file against multiple antivirus engines and threat intelligence feeds without executing it on a live system. This technique is safe as it avoids direct exposure of the production environment to potential malware while leveraging community-sourced detection data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Open the attachment on a production machine

    Why it's wrong here

    Executing or opening an untrusted file directly on an active production system bypasses critical isolation controls, risking immediate compromise of the local host and potential lateral movement across the enterprise network. This reckless action exposes live business assets, sensitive data, and active user credentials to malware execution without any safety net.

  • ✓

    Submit the file to a public online scanner

    Why this is correct

    Uploading the suspicious file to a public multi-engine scanner like VirusTotal allows the analyst to quickly cross-reference the file's hash against dozens of antivirus databases. This provides rapid, low-risk detection intelligence without executing the payload locally, though analysts must remain cautious about leaking sensitive or proprietary data contained within the file.

  • ✗

    Extract and examine the source code of the attachment

    Why it's wrong here

    While static analysis of source code is valuable, attempting to extract and inspect code on a standard workstation carries a high risk of accidental execution, especially with complex file formats or embedded scripts. Furthermore, this manual process is highly time-consuming and inefficient compared to automated triage methods during initial incident response.

  • ✓

    Use an automated malware analysis tool

    Why this is correct

    Utilizing an automated malware analysis platform, such as a dynamic analysis pipeline, allows the security team to safely detonate the file and automatically capture behavioral indicators of compromise (IOCs). This approach accelerates the triage process by generating comprehensive reports on network connections, registry modifications, and process creation without manual intervention.

  • ✓

    Open the attachment in a sandbox environment

    Why this is correct

    Detonating the attachment within a dedicated, isolated sandbox environment allows the analyst to observe the malware's runtime behavior, network callbacks, and file system modifications in real time. Because the sandbox is completely segmented from the production network, any malicious activity is safely contained and can be easily reverted via snapshots.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.