Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is reverse-engineering a .NET binary to understand its authentication logic. Which three tools are suitable for decompiling .NET assemblies? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

dotPeek

dnSpy, ILSpy, and JetBrains dotPeek are decompilers for .NET. Ghidra is for native code, jadx for Android APK.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    jadx

    Why it's wrong here

    jadx targets Java/Dalvik bytecode from Android APKs, specifically disassembling to smali and decompiling to Java. It cannot parse .NET assemblies' metadata tables or CIL bytecode; .NET uses ECMA-335 metadata and MSIL, which jadx doesn't understand. Thus, attempting to load a .NET assembly in jadx would fail or produce nonsense output.

  • ✓

    dotPeek

    Why this is correct

    JetBrains dotPeek is a free .NET decompiler that translates compiled .NET assemblies (CIL bytecode plus metadata) into readable C# source code. It is based on the method bodies and type information stored in the metadata, and it supports modern language features like LINQ and async/await. Beyond decompilation, dotPeek can also display raw IL and generate Visual Studio solutions, making it a complete tool for static analysis of .NET binaries.

  • ✗

    Ghidra

    Why it's wrong here

    Ghidra is a software reverse engineering suite for native machine code (x86, ARM, etc.) and is not designed for managed .NET metadata/CIL. Although Ghidra has a Java decompiler for JVM bytecode, it does not natively parse ECMA-335 assemblies; special extensions or scripting are required to make it handle .NET. Its core analysis models processor instruction sets, not the Common Intermediate Language, so it is the wrong choice for .NET-specific reverse engineering.

  • ✓

    ILSpy

    Why this is correct

    ILSpy is an open-source .NET assembly browser and decompiler, commonly used for reverse engineering managed binaries without licensing costs. It decompiles CIL to C# with high fidelity and offers an integrated IL disassembler, type dependency analysis, and search functionality. However, ILSpy lacks a built-in debugger, so it is primarily for static analysis, unlike dnSpy which adds debugging and patching capabilities.

  • ✓

    dnSpy

    Why this is correct

    dnSpy is a .NET decompiler, debugger, and assembly editor in one, enabling penetration testers to patch or recompile malicious binaries during analysis. It can decompile and then immediately rebuild C# or IL code, with breakpoints, watch windows, and memory inspection for dynamic analysis. This makes it uniquely suited for analyzing malware and understanding obfuscated .NET code, whereas dotPeek and ILSpy are primarily static tools.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.