200-201 Host-Based Analysis Practice Question
A junior analyst is triaging a Windows workstation that users report is running slowly. The analyst suspects a malicious process is persisting by masquerading as a legitimate Windows service. Which built-in Windows tool should the analyst use to view services, their binary paths, and their current state without installing additional software?
⚠ Common exam trap
The trap here is equating Task Manager's process list with a full service inventory, when Task Manager does not reliably show every service's configured binary path or start type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Services console (services.msc)
The Services console (services.msc) is the native Windows management interface that enumerates all installed services and exposes each one's display name, status, start type, and the path to its executable. By reviewing those paths, the analyst can identify a service whose binary resides in an unexpected location, which is a common masquerading persistence method, without deploying any additional tooling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Services console (services.msc)
Why this is correct
The Services console lists every installed Windows service along with its display name, start type, status, and, under the General tab or via the registry, the path to the service binary. This lets the analyst spot a service whose ImagePath points to an unusual directory or executable, which is a classic masquerading persistence technique. It requires no third-party tools.
- ✗
Performance Monitor (perfmon.msc)
Why it's wrong here
Performance Monitor collects and graphs performance counters such as CPU, memory, and disk usage over time. It is useful for diagnosing why the workstation is slow, but it does not display service configurations, binary paths, or start types, so it cannot reveal a service masquerading as a legitimate one.
- ✗
Task Manager's Processes tab
Why it's wrong here
Task Manager shows running processes, resource consumption, and some startup entries, but it does not enumerate Windows services with their configured binary paths or start types. A malicious service that has not yet started or that runs under a different session may not appear clearly, so Task Manager alone is insufficient for verifying service binary paths on this workstation.
- ✗
Event Viewer's Application log
Why it's wrong here
The Application log records events written by applications and some service control manager messages, but it does not present a consolidated inventory of installed services with their executable paths. While service start failures may appear as events, the analyst cannot browse all services and their ImagePath values here, making it unsuitable for this task.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.