CHFI Mobile and Malware Forensics Practice Question
A forensic analyst is performing static analysis of a Windows PE file. Which TWO of the following tools are specifically designed for static analysis of malware?
⚠ Common exam trap
EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse network or process monitoring tools (Wireshark, Process Monitor) with static analysis, or mistake sandboxing (Cuckoo) for static analysis when it is inherently dynamic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IDA Pro
IDA Pro (C) is a disassembler and debugger specifically built for reverse engineering binary executables, allowing an analyst to statically examine a PE file's code, imports, and structure without executing it. Ghidra (D) is the NSA's open-source software reverse engineering suite that likewise performs static disassembly and decompilation of PE files, making it a core static malware analysis tool. Both operate on the file on disk, matching the scenario's requirement for static analysis. Wireshark (A) is a network protocol analyzer that inspects captured traffic, not PE binaries. Cuckoo Sandbox (B) is a dynamic analysis platform that executes malware in an isolated VM and observes behavior, so it is not static. Process Monitor (E) is a live runtime monitoring tool for file, registry, and process activity, also dynamic rather than static.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures and decodes packets from live interfaces or pcap files, focusing on transport-level details such as TCP flags, TLS handshakes, and application payloads. It never parses an executable's on-disk structure, so it cannot reveal opcodes, PE import tables, code sections, or other static artifacts. Because static analysis of a Windows binary requires inspecting its file format and disassembling machine code, Wireshark's network-only scope makes it irrelevant here.
- ✗
Cuckoo Sandbox
Why it's wrong here
Cuckoo Sandbox executes a submitted sample in an isolated virtual machine and observes runtime behavior, including process creation, filesystem writes, registry modifications, and network connections. This means the binary is actually run to analyze its actions, making it a purely dynamic analysis tool. Static analysis, by contrast, examines the file's bytes without executing them, using hashing, PE header inspection, disassembly, and string extraction, none of which Cuckoo performs.
- ✓
IDA Pro
Why this is correct
IDA Pro is an interactive disassembler that converts raw machine code into assembly mnemonics and constructs control-flow and cross-reference graphs, allowing an analyst to understand the binary's logic without running it. It parses the PE/ELF/Mach-O file formats, resolves imports and exports, and identifies function boundaries and string references directly from the file's static content. This aligns exactly with static analysis of a Windows binary because no code is executed; the tool operates solely on the on-disk representation.
- ✓
Ghidra
Why this is correct
Ghidra is a reverse-engineering framework developed by the NSA whose key differentiator is its decompiler, which translates assembly into structured pseudo-C for faster code comprehension. It loads the file in a read-only manner and performs file format parsing, data type inference, and function signature recovery, all without executing the sample. While Ghidra can use emulation plugins to partially handle packed code, its core workflow is inherently static and file-centric, making it a valid choice for analyzing a Windows binary from its bytes.
- ✗
Process Monitor
Why it's wrong here
Process Monitor, or procmon, is a real-time system monitoring utility that logs registry activity, file system operations, and process/thread events only while an executable is actually running. Its data comes from live kernel callbacks and system-wide instrumentation, so analyzing a Windows binary from its file content alone is outside its capabilities. Any task that involves reading the PE header, inspecting embedded strings, or disassembling code is static analysis, which Process Monitor cannot perform because it observes endpoint behavior, not file internals.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.