CS0-003 Incident Response and Management Practice Question
After containing a malware outbreak, the incident response team performs static malware analysis on a suspicious executable. Which of the following artifacts would be most helpful in creating a YARA rule to detect variants of the malware?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The import table showing API calls like WriteProcessMemory and CreateRemoteThread
Import table analysis reveals API calls and DLLs used by the malware, which are often consistent across variants and useful for detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The creation timestamp of the file
Why it's wrong here
File creation timestamps are highly unreliable indicators of compromise because adversaries can easily manipulate them using "timestomping" techniques to match legitimate system files. Relying on metadata like MACB (Modified, Accessed, Created, Born) timestamps in YARA rules would result in fragile signatures that fail to detect modified or newly compiled variants of the malware.
- ✗
The file size of the executable
Why it's wrong here
Executable file size is an ineffective metric for YARA rule creation because minor code modifications, compiler optimizations, or the addition of padding bytes can drastically alter the file size without changing the malware's core functionality. Writing rules based on specific byte counts or file sizes will lead to high false-negative rates when encountering polymorphic variants.
- ✗
The packer used to obfuscate the executable
Why it's wrong here
While identifying a packer like UPX or Themida can indicate obfuscation, writing YARA rules targeting the packer itself is problematic because legitimate software developers also use packers to protect intellectual property. Furthermore, malware authors can easily switch packers or use custom crypters, rendering packer-based signatures obsolete and prone to high false-positive rates on benign packed binaries.
- ✓
The import table showing API calls like WriteProcessMemory and CreateRemoteThread
Why this is correct
Targeting specific Windows API functions within the Portable Executable (PE) import table, such as WriteProcessMemory and CreateRemoteThread, allows YARA rules to identify the underlying functional capabilities of the malware, such as process injection. Because these APIs are essential for the malware's injection mechanism, they serve as robust, behavior-based indicators that remain consistent across different compiled versions and packaging variations.
Go deeper
Related to this question
Learn chapter
Malware Sandboxing and Detonation
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.