PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is reverse-engineering a .NET binary to understand its authentication logic. Which three tools are suitable for decompiling .NET assemblies? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dotPeek
dnSpy, ILSpy, and JetBrains dotPeek are decompilers for .NET. Ghidra is for native code, jadx for Android APK.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
jadx
Why it's wrong here
jadx targets Java/Dalvik bytecode from Android APKs, specifically disassembling to smali and decompiling to Java. It cannot parse .NET assemblies' metadata tables or CIL bytecode; .NET uses ECMA-335 metadata and MSIL, which jadx doesn't understand. Thus, attempting to load a .NET assembly in jadx would fail or produce nonsense output.
- ✓
dotPeek
Why this is correct
JetBrains dotPeek is a free .NET decompiler that translates compiled .NET assemblies (CIL bytecode plus metadata) into readable C# source code. It is based on the method bodies and type information stored in the metadata, and it supports modern language features like LINQ and async/await. Beyond decompilation, dotPeek can also display raw IL and generate Visual Studio solutions, making it a complete tool for static analysis of .NET binaries.
- ✗
Ghidra
Why it's wrong here
Ghidra is a software reverse engineering suite for native machine code (x86, ARM, etc.) and is not designed for managed .NET metadata/CIL. Although Ghidra has a Java decompiler for JVM bytecode, it does not natively parse ECMA-335 assemblies; special extensions or scripting are required to make it handle .NET. Its core analysis models processor instruction sets, not the Common Intermediate Language, so it is the wrong choice for .NET-specific reverse engineering.
- ✓
ILSpy
Why this is correct
ILSpy is an open-source .NET assembly browser and decompiler, commonly used for reverse engineering managed binaries without licensing costs. It decompiles CIL to C# with high fidelity and offers an integrated IL disassembler, type dependency analysis, and search functionality. However, ILSpy lacks a built-in debugger, so it is primarily for static analysis, unlike dnSpy which adds debugging and patching capabilities.
- ✓
dnSpy
Why this is correct
dnSpy is a .NET decompiler, debugger, and assembly editor in one, enabling penetration testers to patch or recompile malicious binaries during analysis. It can decompile and then immediately rebuild C# or IL code, with breakpoints, watch windows, and memory inspection for dynamic analysis. This makes it uniquely suited for analyzing malware and understanding obfuscated .NET code, whereas dotPeek and ILSpy are primarily static tools.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.