CompTIA Security+ (SY0-701)Security OperationsHard
A malware analyst receives a suspicious executable and needs to examine its embedded strings, imported library functions, and file header structure without ever executing the code, in order to minimize risk to the analysis environment. Which technique should the analyst use?
- ANetwork traffic capture during execution
- BStatic analysis
- CDynamic sandboxing
- DBehavioral analysis in a live environment
Show answer & explanationAnswer & explanation
Correct answer: B. Static analysis
Static analysis examines a file's code, strings, headers, and imports without running it, making it the safest way to gather initial indicators before deciding whether further dynamic testing in an isolated sandbox is warranted.
Why the other options are wrong
- A. Capturing network traffic during execution requires the malware to actually run, contradicting the requirement.
- C. Dynamic sandboxing requires executing the code, which is what the analyst wants to avoid at this stage.
- D. Live-environment behavioral analysis involves execution and poses unnecessary risk compared to static inspection.
Static Malware Analysis
Examining a malware sample's code, strings, headers, and structure without executing it, to safely gather indicators of behavior and intent.
- No code execution required
- Includes string extraction, disassembly, and header inspection
- Safer but less revealing than dynamic analysis
- Often performed before dynamic/sandbox analysis
Memory trick: Static stays Still — read the file, never run it