Q: 6
Shane has started the static analysis of a malware and is using the tool ResourcesExtract to find more
details of the malicious program. What part of the analysis is he performing?
Options
Discussion
Option B makes sense. ResourcesExtract pulls embedded resources and string tables from executables, which lines up with a static strings search. Pretty sure about this, not dynamic since he isn’t running the malware. Agree?
Its B. ResourcesExtract pulls out strings and resources from executables, so this would be a static strings search. If it was dynamic analysis we'd need to execute the malware, which isn't the case here.
It isn’t A, B is the right choice.
B, ResourcesExtract isn’t about file dependencies so A is a bit of a trap here imo.
I don’t think it’s A. B fits since ResourcesExtract is mainly for extracting and searching strings, not dependencies.
Probably B - matches what I've seen in other practice sets. The question wording is super clear on this one.
Be respectful. No spam.