Courseiva

CHFI Mobile and Malware Forensics Practice Question

Which of the following is a key difference between static and dynamic malware analysis?

⚠ Common exam trap

It's easy for candidates to confuse the terms 'static' and 'dynamic' by associating 'static' with 'not moving' (incorrectly thinking it means no analysis) or misremembering which one involves execution, leading them to pick Option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Static analysis examines code without execution, dynamic analysis executes the sample

Static malware analysis involves examining the malware's code (e.g., disassembly, strings, headers) without executing it, while dynamic analysis runs the sample in a controlled environment (e.g., sandbox, debugger) to observe its runtime behavior. Option C correctly captures this fundamental distinction: static analysis is code-centric and non-executional, whereas dynamic analysis is behavior-centric and executional.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Static analysis executes the malware, dynamic does not

    Why it's wrong here

    This statement is the exact opposite of the truth. Static analysis is performed on a non-running sample—typically using a disassembler such as IDA Pro or Ghidra to inspect instructions, strings, and metadata—so the malware never executes. Dynamic analysis, conversely, deliberately runs the sample in a controlled sandbox or virtual machine to observe its runtime behavior, such as registry modifications, file system changes, and network connections.

  • ✗

    Static analysis requires an internet connection, dynamic does not

    Why it's wrong here

    Neither static nor dynamic analysis inherently requires an internet connection. Static analysis only reads file bytes, so it is inherently offline. Dynamic analysis often runs in an isolated sandbox that may simulate network services (e.g., INetSim or fake DNS) to trick the malware, but the analysis host itself can be completely disconnected from the internet. Requiring internet would actually be a risk because real malware can exfiltrate data or download additional payloads, so analysts intentionally avoid a live internet link.

  • ✓

    Static analysis examines code without execution, dynamic analysis executes the sample

    Why this is correct

    This is the fundamental distinction between the two analysis categories. Static analysis inspects the binary's code and structure without ever executing it, using techniques like disassembly, decompilation, and string extraction to infer behavior. Dynamic analysis executes the sample in a monitored environment, capturing its actual runtime actions such as API calls, process injection, and file operations, which often reveals behaviors that static analysis alone cannot see.

  • ✗

    Static analysis is always automated, dynamic is manual

    Why it's wrong here

    Automation level is not the defining difference. Static analysis can be highly automated—for example, antivirus engines, YARA rules, or scripts that scan for known signatures—and it can also be a slow, manual reverse-engineering process. Dynamic analysis likewise ranges from fully automated sandboxes like Cuckoo or CAPE, which run samples without human interaction, to manual debugging in x64dbg or WinDbg. Both approaches can be adapted to either manual or automated workflows.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.