Courseiva

CHFI Mobile and Malware Forensics Practice Question

In malware static analysis, a PE file is examined. The section names include '.text', '.rdata', '.data', and '.rsrc'. The entry point is in the .text section. Which tool would be MOST appropriate to identify any packer that might be obfuscating the code?

⚠ Common exam trap

EC-Council often tests the distinction between tools for packer detection versus general reverse engineering; the trap here is that candidates choose IDA Pro or Ghidra because they are powerful, but the question specifically asks for the *most appropriate* tool to *identify* a packer, not to analyze the unpacked code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PEiD

PEiD is specifically designed to detect packers, cryptors, and compilers by scanning PE files for known signatures in the entry point and section headers. Since the question asks for identifying a packer that obfuscates code, PEiD's signature-based detection directly targets this need, unlike general-purpose disassemblers or string extractors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    strings

    Why it's wrong here

    The strings command (or Sysinternals Strings) simply scans a binary for sequences of printable ASCII/Unicode characters. It is used to surface embedded URLs, filenames, or command-line artifacts, but it performs no structural analysis of section headers, entry point code, or entropy. A packed PE file will usually reveal little meaningful text because the actual code and data are compressed, so strings cannot detect or identify the packer itself.

  • ✗

    Ghidra

    Why it's wrong here

    Ghidra is a comprehensive reverse-engineering suite centered on interactive disassembly, decompilation, and scripting. While users can install community plugins to help unpack or identify known packers, Ghidra has no built-in signature scanner dedicated to packer identification; its purpose is to analyze the code that remains after unpacking. PEiD, by contrast, scans entry-point bytes and section names against a packer signature database, making it the pointed tool for this specific triage task.

  • ✓

    PEiD

    Why this is correct

    PEiD (Portable Executable Identifier) is purpose-built for static packer/cryptor/compiler detection by matching the file's entry-point bytes, section names, and structural features against a signature database. It identifies common packers like UPX, ASPack, and MEW, along with compilers, which directly answers the question of whether a PE is packed. This makes it the standard artifact triage tool, despite being dated and sometimes evaded by custom/modified packers.

  • ✗

    IDA Pro

    Why it's wrong here

    IDA Pro is an advanced disassembler and debugger intended for deep binary analysis; it can analyze packed files only after the unpacking routine has been bypassed or dumped. It does not inherently run a packer signature scan on load, and any 'detection' would rely on user-written IDAPython scripts or third-party plugins. PEiD is the correct choice because it automates that signature-matching step before you decide whether to exercise the file's unpacking logic.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.