CompTIA Security+ (SY0-701)Security OperationsEasy
A security administrator is implementing a new security solution that will automatically analyze incoming email attachments for malicious behavior in a safe, isolated environment before they reach user inboxes. Which type of analysis is being performed?
- ASignature-based analysis
- BHeuristic analysis
- CDynamic malware analysis
- DStatic malware analysis
Show answer & explanationAnswer & explanation
Correct answer: C. Dynamic malware analysis
Dynamic malware analysis, often performed in a sandbox, involves executing suspicious code in a controlled environment to observe its real-time behavior. This allows for detection of malware that might evade static or signature-based methods.
Why the other options are wrong
- A. Signature-based analysis compares code against known malware signatures and would not involve executing the attachment to observe new behaviors.
- B. Heuristic analysis uses rules and algorithms to detect suspicious characteristics or behaviors, but 'dynamic' specifically refers to execution in an isolated environment.
- D. Static malware analysis examines code without executing it, looking at strings, headers, and structure, not behavioral execution.
Dynamic Malware Analysis (Sandboxing)
Executing suspicious code in a controlled, isolated environment (sandbox) to observe its real-time behavior and identify malicious actions without risking the production system.
- Observes actual execution behavior.
- Performed in an isolated environment (sandbox).
- Effective against polymorphic and zero-day malware.
Memory trick: To catch a 'dynamic' threat, you need to 'dynamically' run it in a 'sandbox' to see what it 'does'.