mediumMultiple Choice
PT0-002 Practice Question: While analyzing a malicious document, a tester…
While analyzing a malicious document, a tester extracts a VBA macro. Which tool can help decode the macro for analysis?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
oledump
Oledump extracts and analyzes OLE objects, including VBA macros. Option B is wrong because pdf-parser is for PDF analysis. Option C is wrong because Wireshark is for network traffic. Option D is wrong because Nmap is for network scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
oledump
Why this is correct
oledump is the correct tool because it is purpose-built to inspect OLE compound files such as .doc, .xls, and legacy .ppt. It enumerates the internal streams and, with the --vbadecompress flag or the vbadecompress plugin, extracts the compressed VBA macro source code that was stored in the VBA/Compressed stream. This lets an analyst statically review the macro's payload and obfuscation routines without opening the document.
- ✗
pdf-parser
Why it's wrong here
pdf-parser is incorrect because it is designed exclusively for parsing PDF files, not Office binary documents. It dissects PDF objects, streams, and cross-reference tables to uncover embedded JavaScript or anomalous structures. Since a malicious Office document with VBA macros is not a PDF and does not use PDF object syntax, pdf-parser cannot locate or decompress the VBA project stream.
- ✗
Nmap
Why it's wrong here
Nmap is incorrect because it is a network discovery and security auditing tool used for host enumeration, port scanning, and service fingerprinting. It operates at the network layer and has no capability to parse local file formats or extract embedded scripting code. An analyst investigating a malicious document would not use Nmap because its perspective is remote network reconnaissance, not local static file analysis.
- ✗
Wireshark
Why it's wrong here
Wireshark is incorrect because it is a packet analyzer that captures and inspects network traffic on live interfaces or reads previously saved pcap files. It decodes protocols like TCP, HTTP, and TLS, but it has no file-dissector for OLE compound documents and cannot extract VBA macro content. Even if a document was downloaded over a network, Wireshark only sees the raw bytes of the file transfer, not the internal structure of the VBA stream.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.