Courseiva
Security Monitoring →mediumMultiple Select

200-201 Security Monitoring Practice Question

A security analyst is correlating network and endpoint telemetry to detect a host infected with malware that is attempting to establish persistence and communicate externally. Which TWO artifacts would best support this investigation? (Choose two.)

⚠ Common exam trap

The trap here is choosing high-volume sources like all process creation events instead of the targeted registry and flow artifacts that directly evidence persistence and beaconing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sysmon Event ID 13 registry value set events for Run key modifications

To confirm both persistence and external communication, the analyst needs an endpoint artifact that shows the persistence mechanism and a network artifact that shows beaconing. Sysmon registry value set events reveal Run key modifications used for persistence, while NetFlow records expose periodic outbound connections to an external IP. Together they link the infected host's persistence to its command-and-control channel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sysmon Event ID 13 registry value set events for Run key modifications

    Why this is correct

    Sysmon Event ID 13 records registry value set operations, including changes to Run keys, which are a common persistence mechanism. By capturing the process that wrote the value and the exact registry path, analysts can identify which executable will launch at logon. This directly supports the persistence portion of the investigation and links the registry change to a specific process on the infected host.

  • ✓

    NetFlow records showing periodic outbound connections to an external IP

    Why this is correct

    NetFlow provides summarized connection metadata such as source, destination, port, and byte counts without payload. Periodic outbound connections to the same external IP at regular intervals are a strong indicator of command-and-control beaconing. Correlating these flows with the endpoint registry events helps confirm both persistence and external communication from the same host, completing the infection chain picture.

  • ✗

    DHCP server logs showing IP address leases for the subnet

    Why it's wrong here

    DHCP logs map IP addresses to MAC addresses and lease times, which can help identify a host but do not reveal persistence mechanisms or external command-and-control traffic. They are useful for asset attribution during an investigation, but they do not provide the behavioral evidence needed to confirm malware persistence and beaconing. Therefore they are not among the best two artifacts for this scenario.

  • ✗

    Antivirus scan reports from the previous quarter

    Why it's wrong here

    Historical antivirus scan reports show past detections or clean scans but do not capture current persistence changes or live network beaconing. Malware may have been installed after the last scan, and the reports lack the real-time registry and flow data needed to correlate the infection. They are not the most relevant artifacts for confirming active persistence and command-and-control behavior.

  • ✗

    Windows Event ID 4688 process creation events for every process on all hosts

    Why it's wrong here

    Event ID 4688 records process creation but, without additional filtering or command-line auditing enabled, it produces an overwhelming volume of events and lacks the network context needed here. While useful for tracking execution, it does not directly show persistence via Run keys or external beaconing. It is a supporting source rather than one of the two most targeted artifacts for this specific investigation.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.