200-201 › Host-Based Analysis
Host-Based Analysis covers endpoint evidence collection and interpretation on Windows and Linux systems. You must identify malicious processes, persistence mechanisms, and user activity artifacts, then map findings to the correct forensic tool or file location. Questions present investigation scenarios and ask which commands, registry hives, or files reveal the needed evidence.
200-201 Host-Based Analysis — All 165 Questions
Every question in this domain with answers and detailed explanations.