CS0-003 Incident Response and Management Practice Question
An analyst is performing static analysis on a suspicious executable. The analyst discovers that the PE file has a suspicious section name and a high entropy value. Which tool or technique would be MOST useful for further analyzing the packed nature of the file?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using PEiD or similar packer identifier
PEiD or similar tools can detect packers by scanning for known signatures. High entropy and suspicious section names often indicate packing, so using a packer identifier is appropriate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Extracting strings from the binary
Why it's wrong here
While extracting strings using utilities like the strings command can sometimes reveal indicators of packing, such as section names like UPX0 or UPX1, it is not a reliable or definitive method. Packed binaries often obfuscate or compress their string tables, resulting in very few readable strings, which only suggests packing but does not explicitly identify the specific packer used.
- ✗
Using a YARA rule to detect the packer
Why it's wrong here
YARA rules excel at detecting known packers or malware families by matching specific byte patterns, strings, or import functions. While effective for initial identification or classification of a known packer, they do not provide the dynamic analysis capabilities required to further analyse the packing mechanism itself, such as revealing the original, unpacked code or understanding the unpacking routine. The scenario demands deeper inspection beyond mere signature-based detection.
- ✓
Using PEiD or similar packer identifier
Why this is correct
PEiD and similar packer detection tools analyze the Portable Executable (PE) headers, entry point signatures, and section characteristics to quickly and accurately identify specific packers, cryptors, or compilers. This static analysis technique is the most direct and efficient way to confirm if an executable is packed and to determine the exact packing algorithm applied.
- ✗
Running the file in a sandbox
Why it's wrong here
Executing the suspicious binary within a sandbox represents dynamic analysis, which focuses on observing runtime behaviors, network connections, and system modifications. While a sandbox can help analyze the payload once it unpacks itself in memory, it is an inefficient and potentially risky approach for the initial static identification of a packer.
Go deeper
Related to this question
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.