200-201 Host-Based Analysis Practice Question
A security analyst is analyzing a memory dump from a compromised Windows system using Volatility. Which command would best reveal hidden or injected code within a process?
⚠ Common exam trap
200-201 often tests the confusion between process listing (pslist) and memory analysis (malfind) — candidates may pick pslist because it shows processes, but it does not reveal injected code hidden within a legitimate process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
vol.py malfind
The vol.py malfind command in Volatility scans process memory for hidden or injected code by looking for memory regions with suspicious characteristics, such as executable permissions and no corresponding file on disk. It is specifically designed to detect code injection and rootkit-like behavior. This makes it the best choice for revealing hidden or injected code within a process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
vol.py netscan
Why it's wrong here
netscan enumerates network endpoints and sockets from pool tagging, so it cannot surface injected code inside a process's memory. It is tempting because it is the standard Volatility plugin for spotting suspicious connections during incident triage, and would be correct when the question asks which established remote sessions or listening ports a compromised host held.
- ✗
vol.py pslist
Why it's wrong here
pslist enumerates processes from the active process list, which rootkits can unlink, so injected or hidden code stays invisible. It is tempting because it is the standard first listing command, so it would be correct for a quick overview of running processes before deeper scanning with malfind or psscan.
- ✓
vol.py malfind
Why this is correct
The malfind plugin scans process memory for pages exhibiting characteristics of injected or hidden code, such as executable permissions combined with no file backing on disk. This directly targets the scenario's goal of revealing injected code within a process from the memory dump.
- ✗
vol.py dlllist
Why it's wrong here
dlllist walks the loaded-module list in the PEB, so code injected without a corresponding loader entry stays invisible; malfind instead scans for executable pages lacking file backing. It is tempting because dlllist is the natural plugin for enumerating a process's DLLs, and would be correct when asked which libraries a process loaded.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.