These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.
Start Scenario PracticeAn analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about this process? (Choose three.)
Explanation: The `cmdline` plugin displays the command-line arguments used to start a process, which is critical for identifying malicious or suspicious execution patterns (e.g., obfuscated paths, encoded commands). For PID 1337, this reveals exactly how the process was launched, helping to confirm or refute malicious intent.
Given the syslog message, which additional data would best confirm the event as a true positive?
Explanation: The syslog message likely indicates a security event such as a connection to a known malicious IP (203.0.113.10). URL filtering logs provide the specific HTTP/HTTPS request details (e.g., URI, user agent, category) that can confirm whether the traffic was intentional and malicious, rather than a false positive from a benign service or misconfiguration.
During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?
Explanation: Short-term containment should preserve evidence; live imaging captures volatile data before power-off.
A network analyst finds a PCAP with a series of DNS queries for subdomains like "data12345.example.com" and "data67890.example.com" where the subdomain names appear to contain encoded base64 data. This pattern suggests:
Explanation: DNS tunnelling for exfiltration encodes stolen data into DNS query names (often base64) and sends it to an attacker-controlled authoritative DNS server. The pattern of many subdomains with encoded-looking labels under the same domain is a classic indicator of data being smuggled out via DNS, which is frequently allowed through firewalls.
During memory analysis with Volatility, the 'pstree' plugin shows a parent process of 'winlogon.exe' spawning 'cmd.exe'. What is the most likely explanation for this anomaly?
Explanation: Normally, winlogon.exe does not spawn cmd.exe; this could indicate a 'sticky keys' (sethc.exe) persistence or other accessibility tool abuse where cmd.exe replaces the debugger.
+15 more scenario questions available
Practice all Hard Difficulty QuestionsThese are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam. These appear throughout the 200-201 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 200-201. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 200-201 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Hard Difficulty Questions session with instant scoring and detailed explanations.
Start Scenario Practice →