Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is analyzing a suspicious executable found on a compromised Windows host. The tester wants to identify if the executable is packed or obfuscated, which might indicate malware. Which tool is specifically designed for detecting packers and providing information about the executable's structure?

⚠ Common exam trap

The trap here is selecting a network or exploitation tool for binary analysis, when the task specifically requires static inspection of a PE file for packing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PEiD

PEiD is a classic tool for detecting packers and identifying the compiler used to build a PE executable. It works by scanning for known signatures in the executable's entry point and other sections. If the executable is packed, PEiD will often display the packer's name, which is valuable information for malware analysis. This helps the tester understand if the executable is obfuscated and may need to be unpacked before further analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network scanning tool used for host discovery, port scanning, and service enumeration. It does not inspect executable files for packers or obfuscation. It is useful for network reconnaissance but not for static analysis of binaries. The tester's goal is to analyze a file on disk, so Nmap is not appropriate.

  • ✓

    PEiD

    Why this is correct

    PEiD is a tool that detects most common packers, cryptors, and compilers for PE executables. It analyzes the executable's signatures to identify if it is packed and often provides the packer name. In this scenario, the tester can use PEiD to quickly determine if the executable is packed, which is a common characteristic of malware. This helps in deciding the next steps for analysis.

  • ✗

    Metasploit

    Why it's wrong here

    Metasploit is an exploitation framework used for developing and executing exploits against remote targets. It does not provide static analysis of executables for packing detection. While it can deliver payloads, it is not designed to analyze suspicious files. The tester needs a dedicated tool for PE analysis, not an exploitation framework.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer used to capture and inspect network traffic. It does not analyze executable files for packing or obfuscation. While network traffic might reveal command-and-control communication, it cannot determine if a local executable is packed. The tester needs a tool that inspects the binary itself, not network packets.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.