CompTIA SecurityX (CAS-005)Security OperationsMedium
A security operations center (SOC) analyst is investigating a suspected intrusion. They have identified a malicious executable file on a compromised workstation. To understand its full capabilities and indicators of compromise (IOCs) without risking further compromise to the production network, the analyst decides to execute the file in an isolated environment. Which of the following techniques is the analyst employing?
- AStatic Analysis
- BNetwork Packet Capture
- CMemory Forensics
- DDynamic Analysis
Show answer & explanationAnswer & explanation
Correct answer: D. Dynamic Analysis
Executing a malicious file in an isolated environment to observe its behavior is the definition of dynamic analysis. This technique helps in understanding its runtime characteristics and uncovering IOCs.
Why the other options are wrong
- A. Static analysis involves examining the file's code without executing it, which would not reveal runtime behavior.
- B. Network packet capture records network traffic but doesn't involve executing the malicious file itself to understand its internal workings.
- C. Memory forensics involves analyzing the contents of a system's RAM, typically after an incident, not actively executing a file.
Dynamic Malware Analysis
The process of executing a suspicious file in a controlled, isolated environment (e.g., sandbox) to observe its behavior, network communications, file system changes, and process interactions.
- Requires a safe, isolated environment (sandbox).
- Reveals runtime behavior and real-time IOCs.
- Can be time-consuming and requires careful setup.
Memory trick: Static looks at code, Dynamic watches it run.