Courseiva
Security Concepts →mediumMultiple Select

200-201 Security Concepts Practice Question

A security analyst is evaluating an endpoint detection and response deployment for a company that must detect fileless attacks. Which TWO techniques should the analyst expect the tool to monitor because they are commonly used by fileless malware? (Choose two.)

⚠ Common exam trap

The trap here is equating any suspicious-looking Windows activity, such as Kerberos requests or update tasks, with fileless malware, when the defining trait is in-memory execution through trusted system components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WMI event subscription persistence

Fileless malware lives in memory and abuses trusted system components instead of dropping executables on disk. PowerShell is a favorite because it is signed and ubiquitous, and encoded command lines hide the payload from casual inspection. WMI event subscriptions provide persistence that survives reboots without a file artifact. EDR tools therefore focus on process command lines, script block logging, and WMI activity. Disk encryption, antivirus update schedules, and Kerberos TGS requests are not fileless attack techniques and would not be expected monitoring targets for this purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kerberos ticket-granting service requests

    Why it's wrong here

    Kerberos TGS requests are normal authentication events in an Active Directory environment and are monitored for credential abuse such as Kerberoasting, not for fileless malware execution. While they can indicate lateral movement, they do not represent a fileless attack technique. Expecting EDR to treat TGS requests as a fileless malware behavior confuses identity-based attack detection with in-memory code execution detection.

  • ✓

    WMI event subscription persistence

    Why this is correct

    Windows Management Instrumentation allows attackers to create permanent event subscriptions that execute code when triggered, without dropping a traditional executable. Because WMI is a legitimate management component, the malicious subscription can blend into normal activity. EDR products monitor WMI activity, including __EventFilter and CommandLineEventConsumer creation, to catch this common fileless persistence mechanism, so the analyst should expect this coverage.

  • ✓

    PowerShell script execution using encoded commands

    Why this is correct

    Fileless attacks frequently abuse PowerShell because it is a trusted, signed system binary already present on Windows. Attackers run encoded commands with flags such as -EncodedCommand to hide intent and avoid writing a payload to disk. An EDR tool must log PowerShell process creation, command lines, and script block content to detect this behavior, making it a core monitoring target for fileless activity.

  • ✗

    Disk encryption of the system volume

    Why it's wrong here

    Disk encryption such as BitLocker protects data at rest and is a defensive control, not an attack technique. Fileless malware deliberately avoids writing artifacts to disk, so encryption of the volume is unrelated to how the attack executes or persists. Monitoring disk encryption status does not help detect fileless activity and is not a technique used by fileless malware, making this an incorrect expectation.

  • ✗

    Scheduled antivirus signature updates

    Why it's wrong here

    Signature updates are a maintenance function of the antivirus engine and occur on a schedule defined by the product. They are not an attacker technique and do not relate to fileless execution, which evades signature-based detection entirely by living in memory. Expecting EDR to monitor update jobs as a fileless attack vector misidentifies a defensive maintenance task as malicious behavior.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.