Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

During a reverse engineering task on a .NET binary, which tool would allow you to decompile the code into readable C# source code?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

dnSpy

dnSpy is a .NET decompiler that can produce high-level source code from .NET assemblies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IDA Pro Free

    Why it's wrong here

    IDA Pro Free is a limited edition of the Interactive Disassembler that only supports x86/x64 machine-code disassembly and lacks the Hex-Rays decompiler. It does not understand .NET metadata or Common Intermediate Language (CIL), so it would only surface the unmanaged PE stub and native helper functions, not the actual C# assembly logic.

  • ✗

    Ghidra

    Why it's wrong here

    Ghidra is a powerful reverse-engineering framework aimed at native binaries across many processor architectures, using Sleigh disassembly for machine code. While it can decompile to C-like pseudocode, it has no built-in parser for .NET metadata or CIL instructions, so opening a .NET assembly would show the native entry-point stub rather than the managed methods. Dedicated .NET plugins exist but are not part of the standard tool.

  • ✗

    jadx

    Why it's wrong here

    jadx is exclusively tailored for Android reverse engineering, converting DEX bytecode inside APK files into Java source code. It has no capability to load PE files with .NET CLR headers, parse .NET metadata tables, or disassemble CIL, making it entirely unsuitable for a .NET binary reverse-engineering task.

  • ✓

    dnSpy

    Why this is correct

    dnSpy is a purpose-built .NET assembly editor, decompiler, and debugger that can read .NET metadata, decode CIL bytecode, and reconstruct readable C# or VB.NET source code. It also supports editing assemblies in place and debugging managed code, making it the correct choice when the target is a .NET binary.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.