CompTIA Security+ (SY0-701)Security OperationsHard

A SOC analyst receives a suspicious email attachment and wants to observe its behavior, including registry modifications and outbound network connections, before deciding whether to block it organization-wide. The analyst detonates the file inside an isolated virtual machine with no access to production systems. Which technique is being used?

  1. ADynamic malware analysis (sandboxing)
  2. BStatic hash comparison against signatures
  3. CConfiguration compliance scanning
  4. DPassive DNS analysis
Show answer & explanation

Correct answer: A. Dynamic malware analysis (sandboxing)

Dynamic malware analysis, commonly performed in a sandbox, executes suspicious code in an isolated environment to observe real-time behavior such as registry changes and network calls. Static hash comparison only checks for known signatures without executing the file, and the other options are unrelated monitoring techniques.

Why the other options are wrong

  • B. Static analysis compares file hashes to known signatures without execution.
  • C. Configuration compliance scanning checks system settings, not malware behavior.
  • D. Passive DNS analysis reviews historical domain resolution data, not file behavior.

Dynamic Malware Analysis (Sandboxing)

A technique where suspicious files are executed in an isolated environment to observe real-time behavior, such as file system, registry, and network activity, without risking production systems.

  • Detects behavior-based indicators, not just signatures
  • Runs in isolated VM or dedicated sandbox appliance
  • Complements static analysis for comprehensive malware research

Memory trick: Sandboxing lets the malware play in a locked sandbox while defenders watch every move.

More Security Operations questions