Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

A security analyst is investigating a suspicious file and wants to quickly determine whether it is known malware without executing it. Which approach should the analyst use FIRST?

⚠ Common exam trap

EC-CEH often tests the misconception that dynamic analysis (sandboxing) is the fastest initial step, but the trap here is that a hash lookup is both safer and quicker for known malware, while sandboxing is reserved for unknown or suspicious files after a hash check fails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit the file to VirusTotal for hash lookup

Submitting the file's hash to VirusTotal is the fastest and safest first step to determine if the file is known malware. VirusTotal aggregates results from over 70 antivirus engines and threat intelligence feeds, allowing the analyst to check the file's reputation without any risk of execution or analysis overhead. This approach leverages existing threat intelligence to instantly identify known malicious samples, which is the most efficient initial triage step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disassemble the file with IDA Pro

    Why it's wrong here

    Disassembly with IDA Pro reveals code structure but requires expertise and does not confirm malicious identity; it is used for deep reverse engineering after initial triage. Checking the file's hash against threat-intelligence or a multi-engine scanner identifies known malware without execution.

  • ✗

    Check for strings in the binary

    Why it's wrong here

    Extracting strings reveals embedded URLs, filenames and messages, but gives no hash-based identification against known malware databases, so it cannot quickly confirm whether the file is known malware. Strings analysis suits preliminary reconnaissance when hunting for suspicious indicators before reputation lookups.

  • ✗

    Run the file in a sandbox environment

    Why it's wrong here

    Sandbox execution runs the file, which contradicts the requirement not to execute it and risks detonation on the analyst's network. Sandboxes are the right choice when you need behavioural indicators such as network callbacks or registry changes from an unknown sample, after static triage has failed.

  • ✓

    Submit the file to VirusTotal for hash lookup

    Why this is correct

    VirusTotal's hash lookup matches the file's cryptographic fingerprint against aggregated antivirus signatures, confirming known malware without execution. This satisfies the stem's constraint of identifying known threats safely and immediately, since a hash match requires no sandbox detonation or runtime analysis. Unknown files return no match, prompting deeper investigation.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.