Courseiva
mediumMultiple Choice

CS0-003 Practice Question: A SOC analyst receives a file from an unknown…

A SOC analyst receives a file from an unknown source via email. The analyst wants to analyze the file without executing it to determine its functionality. Which type of analysis should be performed?

⚠ Common exam trap

CompTIA often tests the distinction between static and dynamic analysis by emphasizing the 'without executing' condition, leading candidates to confuse behavioral or dynamic analysis as valid options despite the explicit constraint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Static analysis.

Static analysis involves examining a file's code, structure, and metadata without executing it, making it the correct choice for determining functionality while avoiding execution risks. Techniques include inspecting strings, headers, and disassembled code to identify malicious indicators like embedded URLs or API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Behavioral analysis.

    Why it's wrong here

    Behavioral analysis focuses on observing the actions performed by a program, such as registry modifications, file creation, or network connections, during runtime. Because this methodology requires executing the potentially malicious payload to observe its interactions with the operating system, it poses a high risk if performed outside a highly controlled, isolated sandbox environment.

  • ✗

    Memory analysis.

    Why it's wrong here

    Memory analysis, or RAM forensics, involves capturing and inspecting volatile memory to identify active processes, network connections, or injected code. This technique is typically performed post-execution or during an active incident response investigation on a compromised host, making it unsuitable as an initial triage step for an unexecuted, isolated email attachment.

  • ✗

    Dynamic analysis.

    Why it's wrong here

    Dynamic analysis involves executing the suspicious file within a monitored environment, such as a secure sandbox, to observe its live behavior and network traffic. While highly informative, it carries inherent risks of sandbox evasion or accidental network exposure, and it should only be conducted after initial safe triage has been completed.

  • ✓

    Static analysis.

    Why this is correct

    Static analysis is the safest initial step for evaluating an unknown file because it allows the analyst to inspect the file's metadata, PE headers, import tables, and embedded strings without executing the code. By avoiding execution, the analyst eliminates the risk of system infection or triggering anti-analysis logic embedded within the malware.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.