CHFI Mobile and Malware Forensics Practice Question
In static malware analysis, what is the purpose of using a tool like PEiD?
⚠ Common exam trap
EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse PEiD with a disassembler or a runtime monitor, because they see 'analysis' and assume it covers all phases of malware examination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To detect packers or compilers used in the PE file
PEiD is a static analysis tool that identifies packers, cryptors, and compilers embedded in Portable Executable (PE) files by scanning for known signatures in the file's entry point and section headers. This helps an analyst understand whether the malware is packed (obfuscated) and what tool was used to create or compress it, which is critical before attempting dynamic analysis or unpacking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To monitor registry changes during execution
Why it's wrong here
Static analysis is performed in a non-executed environment, so there is no runtime activity to observe. Registry changes only become visible after the sample actually runs, which is why tools such as Regshot and Process Monitor are used during dynamic analysis in a sandboxed VM. Thus, registry-change monitoring is not a purpose of static analysis.
- ✓
To detect packers or compilers used in the PE file
Why this is correct
The tool in question is a static file inspector that examines a PE binary's section names, raw header fields, and byte patterns without executing it. By matching those signatures against known cryptors, packers, and compilers, it identifies protections such as UPX or ASPack, giving the analyst an immediate hint about obfuscation before deeper reverse engineering. That detection directly guides whether unpacking is necessary before disassembly.
- ✗
To disassemble the binary into assembly code
Why it's wrong here
Disassembling the binary into assembly code is an entirely separate static-analysis activity, performed by interactive disassemblers like IDA Pro or Ghidra. The packer-detection utility being described here only scans signatures and does not parse and render machine instructions into a readable assembly listing. So while disassembly is static in nature, it is not the purpose of the tool in question.
- ✗
To analyze network traffic generated by the malware
Why it's wrong here
Network traffic analysis is inherently a post-execution activity because packets are only produced when malware runs and makes outbound connections. Static analysis never executes the sample, so observing network artifacts falls to dynamic tools such as Wireshark, tcpdump, or INetSim in a controlled environment. Therefore, this option describes a dynamic-analysis goal, not a static-file-inspection goal.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.