PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is analyzing a suspicious executable found on a compromised Windows host. The tester wants to identify if the executable is packed or obfuscated, which might indicate malware. Which tool is specifically designed for detecting packers and providing information about the executable's structure?
⚠ Common exam trap
The trap here is selecting a network or exploitation tool for binary analysis, when the task specifically requires static inspection of a PE file for packing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PEiD
PEiD is a classic tool for detecting packers and identifying the compiler used to build a PE executable. It works by scanning for known signatures in the executable's entry point and other sections. If the executable is packed, PEiD will often display the packer's name, which is valuable information for malware analysis. This helps the tester understand if the executable is obfuscated and may need to be unpacked before further analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap
Why it's wrong here
Nmap is a network scanning tool used for host discovery, port scanning, and service enumeration. It does not inspect executable files for packers or obfuscation. It is useful for network reconnaissance but not for static analysis of binaries. The tester's goal is to analyze a file on disk, so Nmap is not appropriate.
- ✓
PEiD
Why this is correct
PEiD is a tool that detects most common packers, cryptors, and compilers for PE executables. It analyzes the executable's signatures to identify if it is packed and often provides the packer name. In this scenario, the tester can use PEiD to quickly determine if the executable is packed, which is a common characteristic of malware. This helps in deciding the next steps for analysis.
- ✗
Metasploit
Why it's wrong here
Metasploit is an exploitation framework used for developing and executing exploits against remote targets. It does not provide static analysis of executables for packing detection. While it can deliver payloads, it is not designed to analyze suspicious files. The tester needs a dedicated tool for PE analysis, not an exploitation framework.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer used to capture and inspect network traffic. It does not analyze executable files for packing or obfuscation. While network traffic might reveal command-and-control communication, it cannot determine if a local executable is packed. The tester needs a tool that inspects the binary itself, not network packets.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.