CS0-003 Incident Response and Management Practice Question
An analyst is reviewing a suspicious executable using static analysis. Which of the following would provide information about the functions the executable imports from system libraries?
⚠ Common exam trap
The trap is confusing PE header analysis with import table analysis — the PE header contains overall metadata, while the import table specifically enumerates functions from system libraries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Import table analysis
The import table (also called the import address table, IAT) lists the functions an executable imports from system libraries (DLLs), such as kernel32.dll or user32.dll. Static analysis of the import table reveals which APIs the malware calls, providing insight into its capabilities (e.g., file I/O, network communication, registry manipulation). This directly answers the question about functions imported from system libraries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Import table analysis
Why this is correct
Import table analysis allows an analyst to inspect the Import Address Table (IAT) of a Portable Executable (PE) file. This reveals the specific dynamic-link libraries (DLLs) and API functions the binary requests from the operating system at runtime. By identifying these imported functions, such as internet connectivity or registry modification APIs, the analyst can infer the program's intended capabilities without executing it.
- ✗
PE header analysis
Why it's wrong here
While PE header analysis provides critical metadata about the executable, such as target architecture, compilation timestamps, and section layouts, it does not directly list the specific API functions imported by the binary. Analysts use header analysis to verify file integrity and identify anomalies like mismatched section sizes, but they must look specifically at the import directory tables to map out external function dependencies.
- ✗
String extraction
Why it's wrong here
String extraction tools like strings pull ASCII and Unicode text from a binary to reveal hardcoded IP addresses, URLs, file paths, or error messages. Although some function names might appear as plain text within these strings, this method cannot reliably map out the structured import dependencies or confirm which APIs are actually linked and called by the executable's import table.
- ✗
YARA rule creation
Why it's wrong here
YARA rule creation is a defensive technique used to classify and identify malware families based on textual or binary patterns. While a YARA rule can be written to match specific import patterns or strings found during analysis, creating the rule itself is a detection mechanism rather than an analytical technique for discovering what functions a suspicious executable imports.
Go deeper
Related to this question
Learn chapter
Communication and Chain of Custody
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.