CompTIA Security+ (SY0-701)Security OperationsEasy

A security administrator is implementing a new security solution that will automatically analyze incoming email attachments for malicious behavior in a safe, isolated environment before they reach user inboxes. Which type of analysis is being performed?

  1. ASignature-based analysis
  2. BHeuristic analysis
  3. CDynamic malware analysis
  4. DStatic malware analysis
Show answer & explanation

Correct answer: C. Dynamic malware analysis

Dynamic malware analysis, often performed in a sandbox, involves executing suspicious code in a controlled environment to observe its real-time behavior. This allows for detection of malware that might evade static or signature-based methods.

Why the other options are wrong

  • A. Signature-based analysis compares code against known malware signatures and would not involve executing the attachment to observe new behaviors.
  • B. Heuristic analysis uses rules and algorithms to detect suspicious characteristics or behaviors, but 'dynamic' specifically refers to execution in an isolated environment.
  • D. Static malware analysis examines code without executing it, looking at strings, headers, and structure, not behavioral execution.

Dynamic Malware Analysis (Sandboxing)

Executing suspicious code in a controlled, isolated environment (sandbox) to observe its real-time behavior and identify malicious actions without risking the production system.

  • Observes actual execution behavior.
  • Performed in an isolated environment (sandbox).
  • Effective against polymorphic and zero-day malware.

Memory trick: To catch a 'dynamic' threat, you need to 'dynamically' run it in a 'sandbox' to see what it 'does'.

More Security Operations questions