Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

A security analyst detects a file named 'invoice.pdf.exe' in an email attachment. When the file is submitted to VirusTotal, multiple engines detect it as a Trojan. The analyst wants to perform dynamic analysis to observe its behavior. Which approach is BEST?

⚠ Common exam trap

EC-CEH often tests the distinction between static and dynamic analysis, and the trap here is that candidates confuse 'submitting to VirusTotal' (a static, signature-based check) with actual behavioral observation, or think disassembly is sufficient to understand runtime behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Execute the file in a sandboxed environment and monitor system calls

Dynamic analysis involves executing malware in a controlled, isolated environment (sandbox) to observe its runtime behavior, such as file system changes, registry modifications, network connections, and process injections. Option C directly enables this by running the Trojan and monitoring system calls, which is the best approach to understand its actual impact and propagation methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disassemble the file using IDA Pro to understand its code

    Why it's wrong here

    Disassembly reveals static instruction flow, not runtime behaviour; the analyst needs to observe process creation, registry writes and network calls as the Trojan executes. IDA Pro is the right tool when reverse-engineering code logic or unpacking a sample without running it, for example to derive IOCs from an obfuscated binary.

  • ✗

    Run 'strings' on the file and analyze the output

    Why it's wrong here

    Strings extracts static embedded text without executing the binary, so no runtime behaviour, registry or network activity is observed. It suits quick triage of scripts; dynamic analysis requires executing the sample in an isolated sandbox with monitoring.

  • ✓

    Execute the file in a sandboxed environment and monitor system calls

    Why this is correct

    Dynamic analysis requires running the malware so its behaviour can be observed. A sandbox isolates execution while capturing system calls, file and registry changes, revealing payload activity that static inspection of the double extension cannot.

  • ✗

    Submit the file again to VirusTotal for a second opinion

    Why it's wrong here

    Resubmitting to VirusTotal returns the same multi-engine verdicts and static metadata; it executes nothing, so no behavioural artefacts such as spawned processes or C2 traffic are captured. VirusTotal is intended for rapid reputation triage and hash lookups, not for observing a sample's actions in a sandbox.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.