CHFI Mobile and Malware Forensics Practice Question
A malware analyst is examining a suspicious Windows executable that appears to be packed. During static analysis, the analyst notices that the PE file has a small number of imports, a high entropy in the .text section, and a section named UPX0. The analyst suspects the sample is packed with UPX. Which TWO of the following techniques would BEST allow the analyst to unpack the sample and continue analysis? (Choose two.)
⚠ Common exam trap
The trap here is believing that renaming a packer section or performing strings analysis can unpack the binary, when unpacking requires either the packer's own decompression routine or runtime memory extraction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run the sample in a sandbox and dump the process memory after it unpacks itself.
UPX-packed executables can be unpacked either by using the UPX utility with the decompress option or by allowing the sample to unpack in memory and then dumping the process. The UPX utility directly reverses the compression if the file is unmodified. Memory dumping captures the unpacked code after the stub runs, which is effective even if the packer was customized. Other methods like strings analysis or section renaming do not achieve unpacking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a debugger to set a breakpoint at the entry point and manually reconstruct the import address table.
Why it's wrong here
While debugging can help unpack manually, simply setting a breakpoint at the entry point and reconstructing the IAT is not a complete unpacking method. The UPX stub will unpack the original code and then transfer control; the analyst would need to identify the original entry point (OEP) and dump memory from there. This approach is more complex and error-prone than using the UPX utility or memory dumping, and it does not directly yield the unpacked binary.
- ✓
Run the sample in a sandbox and dump the process memory after it unpacks itself.
Why this is correct
If the sample is UPX-packed, it will unpack itself in memory during execution. By running it in a controlled sandbox and dumping the process memory after the unpacking stub completes, the analyst can capture the original unpacked code. This technique works even if the UPX utility fails due to modified headers or custom packing, and it provides a memory image that can be analyzed with tools like Volatility or PE-scan.
- ✓
Use the UPX utility with the -d option to decompress the executable.
Why this is correct
UPX is a common packer, and its own utility can unpack executables compressed with it. Running 'upx -d sample.exe' will restore the original binary if it is indeed UPX-packed. This is a quick and reliable method for this specific packer, allowing the analyst to obtain the unpacked code for further static and dynamic analysis without manually reversing the unpacking stub.
- ✗
Perform a strings analysis on the packed binary to extract the original source code.
Why it's wrong here
Strings analysis on a packed binary typically reveals only the packer's strings and possibly some obfuscated data. The original code is compressed or encrypted, so meaningful strings from the malware's logic will not be present. This technique does not unpack the sample and would not allow the analyst to continue analysis of the original code. It is useful for initial triage but not for unpacking.
- ✗
Use a PE editing tool to change the section name from UPX0 to .text and then run the sample.
Why it's wrong here
Renaming a section does not decompress the packed data. The UPX0 section name is a hint, but the actual unpacking is performed by the UPX stub at runtime. Simply renaming the section will not alter the compressed content, and the sample will still execute the unpacking routine. This action would not produce an unpacked binary and could corrupt the file if not done carefully.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.