Courseiva
Host-Based Analysis →hardMultiple Choice

200-201 Host-Based Analysis Practice Question

A CyberOps analyst is examining a Windows workstation and finds that a scheduled task named 'MicrosoftEdgeUpdateTask' exists in Task Scheduler, but the Task Scheduler GUI shows it as disabled. The analyst suspects it was created by malware to masquerade as a legitimate updater. Which artifact should the analyst check to determine the exact executable path and arguments the task would run if it were enabled?

⚠ Common exam trap

The trap here is trusting the disabled state shown in the Task Scheduler GUI, when the underlying XML definition still contains the full malicious action and can be re-enabled at any time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The XML definition of the task, stored under C:\Windows\System32\Tasks and readable with schtasks /query /xml.

The authoritative source for what a scheduled task executes is its XML definition, which lists the action's executable, arguments, and working directory. Reading it directly with schtasks /query /xml bypasses the GUI's disabled display and reveals the true payload. Event logs and file system journals provide timing and creation context but not the task's action content, so they cannot answer what the task would run.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The XML definition of the task, stored under C:\Windows\System32\Tasks and readable with schtasks /query /xml.

    Why this is correct

    Each scheduled task has an XML definition stored in the Tasks folder that contains the complete action list, including the executable path, arguments, working directory, triggers, and principal. Reading it with schtasks /query /xml reveals exactly what the task would run when enabled, regardless of the GUI's disabled indicator, making it the correct artifact to inspect.

  • ✗

    The prefetch file for schtasks.exe located in C:\Windows\Prefetch.

    Why it's wrong here

    Prefetch files document execution of an executable, including run count and referenced files and directories, which can show that schtasks.exe ran and roughly when. They do not contain the command-line arguments passed to schtasks or the resulting task definition, so they cannot reveal what the masquerading task would execute. This artifact supports timeline analysis, not task action extraction.

  • ✗

    The Task Scheduler operational event log (Microsoft-Windows-TaskScheduler/Operational) filtered for Event ID 106.

    Why it's wrong here

    Event ID 106 in the Task Scheduler operational log records that a task was registered, which can reveal creation time and the user context, but it does not store the full action definition such as the executable path and command-line arguments. It is useful for establishing when a task appeared, not for extracting what it would execute, so it does not answer the question.

  • ✗

    The file system journal for the C: volume, queried with fsutil usn readjournal, filtered to the Tasks directory.

    Why it's wrong here

    The USN change journal records file creation, modification, and deletion events with timestamps and reasons, which can show that a task file was written and when. It does not store the contents of the task definition, so it cannot reveal the executable path or arguments the task would run. It is useful for timeline reconstruction, not for extracting task actions.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.