Courseiva
Malware Forensics →mediumMultiple Choice

CHFI Malware Forensics Practice Question

A forensic examiner is analyzing a potentially malicious Portable Executable (PE) file recovered from a compromised host. The examiner uses PEStudio to inspect the file and notices that the Import Address Table (IAT) contains only two functions: LoadLibraryA and GetProcAddress. Which of the following does this most likely indicate?

⚠ Common exam trap

The trap here is assuming that a minimal import table is due to packing or a legitimate optimization, when it specifically indicates dynamic API resolution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The malware uses dynamic API resolution to hide its true capabilities from static analysis tools.

A PE file that imports only LoadLibraryA and GetProcAddress is highly suspicious because it suggests the malware dynamically resolves other API calls at runtime. This technique hides the true functionality from static analysis, as the actual functions used are not visible in the import table. Investigators must use dynamic analysis or memory forensics to reveal the full behavior. This is a common evasion tactic in malware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file is a legitimate system component that relies on dynamic linking for performance optimization.

    Why it's wrong here

    Legitimate system components typically import numerous functions from various DLLs, not just two. Relying solely on LoadLibraryA and GetProcAddress is unusual for normal binaries and is a hallmark of malware attempting to hide its functionality. Performance optimization does not explain such a minimal import table; such optimization would still require additional imports for core functionality.

  • ✓

    The malware uses dynamic API resolution to hide its true capabilities from static analysis tools.

    Why this is correct

    When a PE file imports only LoadLibraryA and GetProcAddress, it indicates that the malware resolves other API functions at runtime. This technique, known as dynamic API resolution, evades static analysis because the actual functions used are not listed in the import table. Analysts must then resort to dynamic analysis or manual unpacking to uncover the full behavior of the sample.

  • ✗

    The malware is written in a high-level language such as C#, which compiles to a .NET assembly and has a minimal IAT.

    Why it's wrong here

    A .NET assembly would not have a traditional PE import table like native executables; it would have a CLR header and metadata. The presence of LoadLibraryA and GetProcAddress in the IAT suggests a native binary, not a managed .NET assembly. Thus, this option incorrectly attributes the characteristic to a .NET compilation artifact.

  • ✗

    The file is packed with a commercial packer, which automatically reduces the import table to these two functions.

    Why it's wrong here

    While packers often obscure imports, they typically still leave a minimal set of imports needed for unpacking, which may include more than just LoadLibraryA and GetProcAddress. The presence of only these two functions is more specifically indicative of deliberate dynamic API resolution rather than a generic packer artifact. Assuming a packer here would be a premature conclusion.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.