200-201 Host-Based Analysis Practice Question
A security analyst is analyzing a Linux system suspected of being used as a phishing server. Which THREE artifacts should the analyst examine to identify persistence mechanisms? (Select 3)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/etc/systemd/system/
Common Linux persistence mechanisms include cron jobs (crontab), systemd services, and startup scripts. Bash history may show commands but is not a persistence mechanism itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/var/log/auth.log
Why it's wrong here
auth.log records authentication events such as logins and sudo use, which reveal access attempts but not the scheduled jobs, services or startup scripts that re-execute malware after reboot. It is tempting because it exposes attacker activity, yet persistence identification relies on cron, systemd units and init files instead.
- ✓
/etc/systemd/system/
Why this is correct
The /etc/systemd/system/ directory holds administrator-defined systemd unit files, including custom services and timers that start automatically at boot. Examining it reveals malicious units an attacker added for persistence, satisfying the requirement to identify persistence mechanisms on the compromised Linux phishing server.
- ✓
/etc/rc.local
Why this is correct
/etc/rc.local executes commands at the end of each multi-user runlevel boot, so any malicious entry there survives reboots — exactly the persistence the analyst must identify on the compromised Linux phishing server. Its contents reveal attacker-added startup commands that would otherwise be missed when tracing how the host maintains its foothold.
- ✗
~/.bash_history
Why it's wrong here
bash_history shows commands typed interactively, which may hint at how malware was installed, but it captures no mechanism that automatically restarts on boot. It is tempting because it can reveal attacker tooling, yet persistence requires examining cron jobs, systemd units or rc scripts rather than shell command history.
- ✓
/etc/crontab
Why this is correct
/etc/crontab defines scheduled jobs run by cron, allowing an attacker to execute malicious commands at recurring intervals. Scheduled entries here persist across reboots, so examining this file reveals time-based persistence mechanisms on the compromised host.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.