CHFI Malware Forensics Practice Question
A forensic examiner is analyzing a potentially malicious Portable Executable (PE) file recovered from a compromised host. The examiner uses PEStudio to inspect the file and notices that the Import Address Table (IAT) contains only two functions: LoadLibraryA and GetProcAddress. Which of the following does this most likely indicate?
⚠ Common exam trap
The trap here is assuming that a minimal import table is due to packing or a legitimate optimization, when it specifically indicates dynamic API resolution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The malware uses dynamic API resolution to hide its true capabilities from static analysis tools.
A PE file that imports only LoadLibraryA and GetProcAddress is highly suspicious because it suggests the malware dynamically resolves other API calls at runtime. This technique hides the true functionality from static analysis, as the actual functions used are not visible in the import table. Investigators must use dynamic analysis or memory forensics to reveal the full behavior. This is a common evasion tactic in malware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The file is a legitimate system component that relies on dynamic linking for performance optimization.
Why it's wrong here
Legitimate system components typically import numerous functions from various DLLs, not just two. Relying solely on LoadLibraryA and GetProcAddress is unusual for normal binaries and is a hallmark of malware attempting to hide its functionality. Performance optimization does not explain such a minimal import table; such optimization would still require additional imports for core functionality.
- ✓
The malware uses dynamic API resolution to hide its true capabilities from static analysis tools.
Why this is correct
When a PE file imports only LoadLibraryA and GetProcAddress, it indicates that the malware resolves other API functions at runtime. This technique, known as dynamic API resolution, evades static analysis because the actual functions used are not listed in the import table. Analysts must then resort to dynamic analysis or manual unpacking to uncover the full behavior of the sample.
- ✗
The malware is written in a high-level language such as C#, which compiles to a .NET assembly and has a minimal IAT.
Why it's wrong here
A .NET assembly would not have a traditional PE import table like native executables; it would have a CLR header and metadata. The presence of LoadLibraryA and GetProcAddress in the IAT suggests a native binary, not a managed .NET assembly. Thus, this option incorrectly attributes the characteristic to a .NET compilation artifact.
- ✗
The file is packed with a commercial packer, which automatically reduces the import table to these two functions.
Why it's wrong here
While packers often obscure imports, they typically still leave a minimal set of imports needed for unpacking, which may include more than just LoadLibraryA and GetProcAddress. The presence of only these two functions is more specifically indicative of deliberate dynamic API resolution rather than a generic packer artifact. Assuming a packer here would be a premature conclusion.
Visual reference
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
RAM Analysis
RAM Analysis is the forensic examination of a computer’s volatile memory to uncover evidence of running processes, network connections, malware, and user activity that is lost when the system is powered off.
Key term
Volatility Framework
An open-source memory forensics tool used to extract digital evidence from a computer's RAM (random access memory).
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.