Courseiva

CHFI Mobile and Malware Forensics Practice Question

A forensic analyst is performing static analysis of a Windows PE file. Which TWO of the following tools are specifically designed for static analysis of malware?

⚠ Common exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse network or process monitoring tools (Wireshark, Process Monitor) with static analysis, or mistake sandboxing (Cuckoo) for static analysis when it is inherently dynamic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IDA Pro

IDA Pro (C) is a disassembler and debugger specifically built for reverse engineering binary executables, allowing an analyst to statically examine a PE file's code, imports, and structure without executing it. Ghidra (D) is the NSA's open-source software reverse engineering suite that likewise performs static disassembly and decompilation of PE files, making it a core static malware analysis tool. Both operate on the file on disk, matching the scenario's requirement for static analysis. Wireshark (A) is a network protocol analyzer that inspects captured traffic, not PE binaries. Cuckoo Sandbox (B) is a dynamic analysis platform that executes malware in an isolated VM and observes behavior, so it is not static. Process Monitor (E) is a live runtime monitoring tool for file, registry, and process activity, also dynamic rather than static.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer that captures and decodes packets from live interfaces or pcap files, focusing on transport-level details such as TCP flags, TLS handshakes, and application payloads. It never parses an executable's on-disk structure, so it cannot reveal opcodes, PE import tables, code sections, or other static artifacts. Because static analysis of a Windows binary requires inspecting its file format and disassembling machine code, Wireshark's network-only scope makes it irrelevant here.

  • ✗

    Cuckoo Sandbox

    Why it's wrong here

    Cuckoo Sandbox executes a submitted sample in an isolated virtual machine and observes runtime behavior, including process creation, filesystem writes, registry modifications, and network connections. This means the binary is actually run to analyze its actions, making it a purely dynamic analysis tool. Static analysis, by contrast, examines the file's bytes without executing them, using hashing, PE header inspection, disassembly, and string extraction, none of which Cuckoo performs.

  • ✓

    IDA Pro

    Why this is correct

    IDA Pro is an interactive disassembler that converts raw machine code into assembly mnemonics and constructs control-flow and cross-reference graphs, allowing an analyst to understand the binary's logic without running it. It parses the PE/ELF/Mach-O file formats, resolves imports and exports, and identifies function boundaries and string references directly from the file's static content. This aligns exactly with static analysis of a Windows binary because no code is executed; the tool operates solely on the on-disk representation.

  • ✓

    Ghidra

    Why this is correct

    Ghidra is a reverse-engineering framework developed by the NSA whose key differentiator is its decompiler, which translates assembly into structured pseudo-C for faster code comprehension. It loads the file in a read-only manner and performs file format parsing, data type inference, and function signature recovery, all without executing the sample. While Ghidra can use emulation plugins to partially handle packed code, its core workflow is inherently static and file-centric, making it a valid choice for analyzing a Windows binary from its bytes.

  • ✗

    Process Monitor

    Why it's wrong here

    Process Monitor, or procmon, is a real-time system monitoring utility that logs registry activity, file system operations, and process/thread events only while an executable is actually running. Its data comes from live kernel callbacks and system-wide instrumentation, so analyzing a Windows binary from its file content alone is outside its capabilities. Any task that involves reading the PE header, inspecting embedded strings, or disassembling code is static analysis, which Process Monitor cannot perform because it observes endpoint behavior, not file internals.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.