Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

A malware analyst wants to examine a suspicious executable without executing it. The goal is to extract strings, view the PE header, and check for known signatures. Which approach is the analyst using?

⚠ Common exam trap

The CEH exam often tests the distinction between static and dynamic analysis, and the trap here is that candidates confuse 'reverse engineering' as a synonym for static analysis, but reverse engineering is a superset that includes both static and dynamic methods, whereas the question specifically describes non-execution inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Static analysis

Static analysis involves examining a binary without executing it. The analyst extracts strings (e.g., using `strings`), views the PE header (e.g., with `pefile` or `dumpbin`), and checks for known signatures (e.g., YARA rules or antivirus hashes). This approach is safe and preserves the original state of the file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Static analysis

    Why this is correct

    Static analysis inspects the binary's code and structure without running it, allowing extraction of strings, PE header fields and signature matches. This directly satisfies the constraint of examining the executable without executing it, unlike dynamic or behavioural analysis.

  • ✗

    Dynamic analysis

    Why it's wrong here

    Dynamic analysis executes the sample in a sandbox and observes runtime behaviour, which the stem explicitly excludes. It is tempting because it also examines malware, but string extraction, PE header inspection and signature checks are static analysis techniques performed without running the executable.

  • ✗

    Heuristic analysis

    Why it's wrong here

    Heuristic analysis judges behaviour by executing the sample in a sandbox and watching for suspicious actions, so it cannot extract strings or read a PE header statically. It is tempting because heuristics detect novel, signature-less malware, which would be the right approach when the goal is behavioural detection rather than static inspection.

  • ✗

    Reverse engineering

    Why it's wrong here

    Reverse engineering means disassembling code to recover logic, not the lighter static triage of strings, PE headers and signature checks described. It is tempting because it also avoids execution, and would be correct when the analyst must understand the malware's internal algorithms or defeat obfuscation.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.