Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is analyzing a Linux binary and wants to decompile it to understand its logic. Which open-source tool is specifically designed for reverse engineering and can generate C-like pseudocode from compiled binaries?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ghidra

Ghidra, developed by the NSA, is a reverse engineering framework that can decompile binaries into C-like pseudocode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IDA Pro Free

    Why it's wrong here

    IDA Pro Free is a robust disassembler that supports many architectures, but the free version omits the Hex-Rays decompiler plugin. Without Hex-Rays, the analyst is limited to low-level assembly listings and cannot generate the high-level C-like pseudocode that would streamline comprehension of a Linux binary's logic. Thus, although it may be useful for some analysis, it fails to provide the decompilation capability central to this task.

  • ✗

    dnSpy

    Why it's wrong here

    dnSpy is a specialized .NET assembly browser and decompiler, designed to reverse-engineer managed code such as C# or VB.NET that is compiled to Common Intermediate Language (CIL). It cannot parse native Linux ELF executables, which are typically produced from C/C++ and contain machine code for a specific CPU architecture. Since the target is a Linux binary, dnSpy is entirely unsuitable for this engagement.

  • ✓

    Ghidra

    Why this is correct

    Ghidra is a free, open-source reverse-engineering suite developed by the NSA and includes a built-in decompiler that converts machine code into approximate C pseudocode. It supports a broad range of architectures and runs natively on Linux, making it ideal for analyzing ELF binaries. The decompiler output, though not perfect, dramatically accelerates understanding of program flow and logic, which is exactly what a penetration tester needs.

  • ✗

    jadx

    Why it's wrong here

    jadx is a tool narrowly focused on decompiling Android APK files by converting DEX bytecode into Java source code. It expects input in Android's Dex format and cannot handle native Linux ELF executables, as it has no support for machine-code architectures like x86 or ARM. Therefore, jadx would reject a Linux binary immediately and provide no useful analysis for this task.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.