Courseiva

CS0-003 Incident Response and Management Practice Question

After containing a malware outbreak, the incident response team performs static malware analysis on a suspicious executable. Which of the following artifacts would be most helpful in creating a YARA rule to detect variants of the malware?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The import table showing API calls like WriteProcessMemory and CreateRemoteThread

Import table analysis reveals API calls and DLLs used by the malware, which are often consistent across variants and useful for detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The creation timestamp of the file

    Why it's wrong here

    File creation timestamps are highly unreliable indicators of compromise because adversaries can easily manipulate them using "timestomping" techniques to match legitimate system files. Relying on metadata like MACB (Modified, Accessed, Created, Born) timestamps in YARA rules would result in fragile signatures that fail to detect modified or newly compiled variants of the malware.

  • ✗

    The file size of the executable

    Why it's wrong here

    Executable file size is an ineffective metric for YARA rule creation because minor code modifications, compiler optimizations, or the addition of padding bytes can drastically alter the file size without changing the malware's core functionality. Writing rules based on specific byte counts or file sizes will lead to high false-negative rates when encountering polymorphic variants.

  • ✗

    The packer used to obfuscate the executable

    Why it's wrong here

    While identifying a packer like UPX or Themida can indicate obfuscation, writing YARA rules targeting the packer itself is problematic because legitimate software developers also use packers to protect intellectual property. Furthermore, malware authors can easily switch packers or use custom crypters, rendering packer-based signatures obsolete and prone to high false-positive rates on benign packed binaries.

  • ✓

    The import table showing API calls like WriteProcessMemory and CreateRemoteThread

    Why this is correct

    Targeting specific Windows API functions within the Portable Executable (PE) import table, such as WriteProcessMemory and CreateRemoteThread, allows YARA rules to identify the underlying functional capabilities of the malware, such as process injection. Because these APIs are essential for the malware's injection mechanism, they serve as robust, behavior-based indicators that remain consistent across different compiled versions and packaging variations.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.