Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 112-57 Exam - Topic 7 Question 10 Discussion

Williams, a forensic specialist, was tasked with performing a static malware analysis on a suspect system in an organization. For this purpose, Williams used an automated tool to perform a string search and saved all the identified strings in a text file. After analyzing the strings, he determined all the harmful actions that were performed by malware.Identify the tool employed by Williams in the above scenario.
B) ResourcesExtract
A) R-Drive Image
C) Ezvid
D) Snagit

Eccouncil 112-57 Exam - Topic 7 Question 10 Discussion

Actual exam question for Eccouncil's 112-57 exam
Question #: 10
Topic #: 7
[All 112-57 Questions]

Williams, a forensic specialist, was tasked with performing a static malware analysis on a suspect system in an organization. For this purpose, Williams used an automated tool to perform a string search and saved all the identified strings in a text file. After analyzing the strings, he determined all the harmful actions that were performed by malware.

Identify the tool employed by Williams in the above scenario.

Show Suggested Answer Hide Answer
Suggested Answer: B

In static malware analysis, one of the quickest ways to infer capability is to extract and review strings embedded in a binary. Strings frequently reveal command-and-control domains/IPs, mutex names, file paths, registry keys, user-agent values, suspicious commands (PowerShell/cmd), API names, error messages, encryption markers, and configuration fragments. Investigators often use automated utilities to extract these readable artifacts and export them to a text file for later triage, keyword searching, and correlation with other evidence (network logs, endpoint telemetry, and threat intel).

Among the provided options, ResourcesExtract best matches this workflow. It is designed to extract embedded content from executable files---particularly Windows PE resources---and can export extracted textual items (including resource strings/strings tables and related embedded text) into external files for analysis. This aligns with ''performed a string search and saved all the identified strings in a text file.''

The other choices do not fit: R-Drive Image is a disk imaging/backup tool; Ezvid is for screen recording; and Snagit is for screenshots/screen capture. They do not perform automated extraction of strings from malware binaries as a static-analysis step. Therefore, the correct answer is ResourcesExtract (B).


Contribute your Thoughts:

0/2000 characters
Genevieve
5 hours ago
Definitely B) ResourcesExtract, it's perfect for string searches.
upvoted 0 times
...
Felton
5 days ago
ResourcesExtract sounds right since it’s specifically designed to extract strings from files, but I could be mixing it up with another tool.
upvoted 0 times
...
Lina
11 days ago
I feel like Ezvid and Snagit are more for video and screen capture, so they wouldn't fit this scenario at all.
upvoted 0 times
...
Josephine
16 days ago
I remember practicing with similar questions, and I think R-Drive Image is more for disk imaging, not string analysis.
upvoted 0 times
...
Milly
2 months ago
I think the tool used for string searching in malware analysis is likely ResourcesExtract, but I'm not completely sure.
upvoted 0 times
...

Save Cancel