Courseiva

CHFI Mobile and Malware Forensics Practice Question

Which of the following is the primary purpose of performing static analysis on a suspicious binary?

⚠ Common exam trap

EC-Council often tests the distinction between static and dynamic analysis, trapping candidates who confuse observing runtime behavior (dynamic) with examining code without execution (static).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analysing the binary's code and structure without executing it

Static analysis examines a binary's code and structure without executing it, allowing analysts to identify malicious indicators such as embedded strings, import tables, and cryptographic constants. This approach avoids triggering anti-analysis mechanisms that activate upon execution, making it a foundational step in malware forensics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Capturing network traffic generated by the binary

    Why it's wrong here

    Network traffic capture is a dynamic analysis technique that requires executing the binary to observe outbound connections, DNS queries, and payload data. Because static analysis involves examining the file in a dormant state, any technique that relies on runtime execution—like triggering network activity—falls outside its scope. This approach is nonetheless critical for identifying C2 endpoints and data exfiltration, but it is a separate phase performed after static inspection.

  • ✗

    Observing the binary's runtime behaviour in a sandbox

    Why it's wrong here

    Observing the binary's runtime behaviour in a sandbox describes dynamic analysis, where the sample is executed in a controlled environment to log API calls, file modifications, registry changes, and process memory. Static analysis, by definition, does not execute the binary; instead it inspects the file's headers, strings, imports, and disassembled instructions to infer functionality. Sandboxing is invaluable for confirming hypotheses and detecting anti-detection tricks, but it contradicts the 'without executing' premise of static analysis.

  • ✓

    Analysing the binary's code and structure without executing it

    Why this is correct

    Static analysis is the process of examining a binary without executing it, focusing on its structural and code-level characteristics. This includes parsing file headers (PE/ELF), analysing import and export tables, extracting readable strings, detecting packers, and disassembling or decompiling code into control flow graphs. The goal is to understand the program's functionality, capabilities, and potential vulnerabilities purely from its inert representation, making it safe for initial triage of unknown or malicious files.

  • ✗

    Modifying the binary to bypass anti-analysis techniques

    Why it's wrong here

    Modifying a binary, such as patching anti-debugging checks or unpacking code in memory, is a form of binary instrumentation or dynamic patching, not a static analysis activity. Static analysis aims to derive understanding from the original, unmodified file; altering the binary introduces changes that could invalidate findings and is typically performed to enable further dynamic or debugging sessions. While bypassing anti-analysis is a real concern in malware research, it is not the primary goal of static analysis, which seeks to interpret the code as it exists.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.