CHFI Mobile and Malware Forensics Practice Question
In malware static analysis, a PE file is examined. The section names include '.text', '.rdata', '.data', and '.rsrc'. The entry point is in the .text section. Which tool would be MOST appropriate to identify any packer that might be obfuscating the code?
⚠ Common exam trap
EC-Council often tests the distinction between tools for packer detection versus general reverse engineering; the trap here is that candidates choose IDA Pro or Ghidra because they are powerful, but the question specifically asks for the *most appropriate* tool to *identify* a packer, not to analyze the unpacked code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PEiD
PEiD is specifically designed to detect packers, cryptors, and compilers by scanning PE files for known signatures in the entry point and section headers. Since the question asks for identifying a packer that obfuscates code, PEiD's signature-based detection directly targets this need, unlike general-purpose disassemblers or string extractors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
strings
Why it's wrong here
The strings command (or Sysinternals Strings) simply scans a binary for sequences of printable ASCII/Unicode characters. It is used to surface embedded URLs, filenames, or command-line artifacts, but it performs no structural analysis of section headers, entry point code, or entropy. A packed PE file will usually reveal little meaningful text because the actual code and data are compressed, so strings cannot detect or identify the packer itself.
- ✗
Ghidra
Why it's wrong here
Ghidra is a comprehensive reverse-engineering suite centered on interactive disassembly, decompilation, and scripting. While users can install community plugins to help unpack or identify known packers, Ghidra has no built-in signature scanner dedicated to packer identification; its purpose is to analyze the code that remains after unpacking. PEiD, by contrast, scans entry-point bytes and section names against a packer signature database, making it the pointed tool for this specific triage task.
- ✓
PEiD
Why this is correct
PEiD (Portable Executable Identifier) is purpose-built for static packer/cryptor/compiler detection by matching the file's entry-point bytes, section names, and structural features against a signature database. It identifies common packers like UPX, ASPack, and MEW, along with compilers, which directly answers the question of whether a PE is packed. This makes it the standard artifact triage tool, despite being dated and sometimes evaded by custom/modified packers.
- ✗
IDA Pro
Why it's wrong here
IDA Pro is an advanced disassembler and debugger intended for deep binary analysis; it can analyze packed files only after the unpacking routine has been bypassed or dumped. It does not inherently run a packer signature scan on load, and any 'detection' would rely on user-written IDAPython scripts or third-party plugins. PEiD is the correct choice because it automates that signature-matching step before you decide whether to exercise the file's unpacking logic.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.