CS0-003 Incident Response and Management Practice Question
An analyst is using YARA to create rules for detecting a specific malware strain. Which of the following pieces of information is MOST useful for writing a YARA rule?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A unique string within the malware.
YARA rules are based on patterns in the file, such as strings and byte sequences. A unique string found in the malware sample can be used to create a rule that identifies the malware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The malware's file size.
Why it's wrong here
While YARA rules can evaluate file size using the filesize keyword in the condition section, relying on file size alone is highly ineffective. Attackers can easily modify file sizes by appending padding or junk bytes, making this metric far too generic and prone to false positives or bypasses.
- ✗
The date the malware was first seen.
Why it's wrong here
First-seen timestamps are metadata tracked by threat intelligence platforms and malware repositories, not intrinsic properties of the file itself. YARA rules analyze the internal structure, strings, and binary patterns of a file, making external temporal metadata irrelevant to the rule's signature matching engine.
- ✓
A unique string within the malware.
Why this is correct
YARA is primarily a pattern-matching tool designed to identify malware families based on textual or hexadecimal patterns. Defining unique strings, such as specific registry keys, user-agent strings, or unique function names within the rule's string section, allows the engine to reliably flag files belonging to that specific malware family.
- ✗
The malware's MD5 hash.
Why it's wrong here
Although YARA can calculate and match hashes using the Hash module, using an MD5 hash defeats the tool's primary purpose of heuristic, pattern-based detection. A simple one-byte change in the malware's code completely alters its MD5 hash, rendering hash-based rules useless against polymorphic or slightly modified variants.
Go deeper
Related to this question
Learn chapter
SIGMA and YARA Detection Rules
Key term
YARA
YARA is a pattern-matching tool used by cybersecurity professionals to identify and classify malware based on textual or binary patterns.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.