Courseiva

CS0-003 Incident Response and Management Practice Question

An analyst is reviewing a suspicious executable using static analysis. Which of the following would provide information about the functions the executable imports from system libraries?

⚠ Common exam trap

The trap is confusing PE header analysis with import table analysis — the PE header contains overall metadata, while the import table specifically enumerates functions from system libraries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Import table analysis

The import table (also called the import address table, IAT) lists the functions an executable imports from system libraries (DLLs), such as kernel32.dll or user32.dll. Static analysis of the import table reveals which APIs the malware calls, providing insight into its capabilities (e.g., file I/O, network communication, registry manipulation). This directly answers the question about functions imported from system libraries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Import table analysis

    Why this is correct

    Import table analysis allows an analyst to inspect the Import Address Table (IAT) of a Portable Executable (PE) file. This reveals the specific dynamic-link libraries (DLLs) and API functions the binary requests from the operating system at runtime. By identifying these imported functions, such as internet connectivity or registry modification APIs, the analyst can infer the program's intended capabilities without executing it.

  • ✗

    PE header analysis

    Why it's wrong here

    While PE header analysis provides critical metadata about the executable, such as target architecture, compilation timestamps, and section layouts, it does not directly list the specific API functions imported by the binary. Analysts use header analysis to verify file integrity and identify anomalies like mismatched section sizes, but they must look specifically at the import directory tables to map out external function dependencies.

  • ✗

    String extraction

    Why it's wrong here

    String extraction tools like strings pull ASCII and Unicode text from a binary to reveal hardcoded IP addresses, URLs, file paths, or error messages. Although some function names might appear as plain text within these strings, this method cannot reliably map out the structured import dependencies or confirm which APIs are actually linked and called by the executable's import table.

  • ✗

    YARA rule creation

    Why it's wrong here

    YARA rule creation is a defensive technique used to classify and identify malware families based on textual or binary patterns. While a YARA rule can be written to match specific import patterns or strings found during analysis, creating the rule itself is a detection mechanism rather than an analytical technique for discovering what functions a suspicious executable imports.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.