200-201 Security Concepts Practice Question
A security analyst is evaluating an endpoint detection and response deployment for a company that must detect fileless attacks. Which TWO techniques should the analyst expect the tool to monitor because they are commonly used by fileless malware? (Choose two.)
⚠ Common exam trap
The trap here is equating any suspicious-looking Windows activity, such as Kerberos requests or update tasks, with fileless malware, when the defining trait is in-memory execution through trusted system components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WMI event subscription persistence
Fileless malware lives in memory and abuses trusted system components instead of dropping executables on disk. PowerShell is a favorite because it is signed and ubiquitous, and encoded command lines hide the payload from casual inspection. WMI event subscriptions provide persistence that survives reboots without a file artifact. EDR tools therefore focus on process command lines, script block logging, and WMI activity. Disk encryption, antivirus update schedules, and Kerberos TGS requests are not fileless attack techniques and would not be expected monitoring targets for this purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kerberos ticket-granting service requests
Why it's wrong here
Kerberos TGS requests are normal authentication events in an Active Directory environment and are monitored for credential abuse such as Kerberoasting, not for fileless malware execution. While they can indicate lateral movement, they do not represent a fileless attack technique. Expecting EDR to treat TGS requests as a fileless malware behavior confuses identity-based attack detection with in-memory code execution detection.
- ✓
WMI event subscription persistence
Why this is correct
Windows Management Instrumentation allows attackers to create permanent event subscriptions that execute code when triggered, without dropping a traditional executable. Because WMI is a legitimate management component, the malicious subscription can blend into normal activity. EDR products monitor WMI activity, including __EventFilter and CommandLineEventConsumer creation, to catch this common fileless persistence mechanism, so the analyst should expect this coverage.
- ✓
PowerShell script execution using encoded commands
Why this is correct
Fileless attacks frequently abuse PowerShell because it is a trusted, signed system binary already present on Windows. Attackers run encoded commands with flags such as -EncodedCommand to hide intent and avoid writing a payload to disk. An EDR tool must log PowerShell process creation, command lines, and script block content to detect this behavior, making it a core monitoring target for fileless activity.
- ✗
Disk encryption of the system volume
Why it's wrong here
Disk encryption such as BitLocker protects data at rest and is a defensive control, not an attack technique. Fileless malware deliberately avoids writing artifacts to disk, so encryption of the volume is unrelated to how the attack executes or persists. Monitoring disk encryption status does not help detect fileless activity and is not a technique used by fileless malware, making this an incorrect expectation.
- ✗
Scheduled antivirus signature updates
Why it's wrong here
Signature updates are a maintenance function of the antivirus engine and occur on a schedule defined by the product. They are not an attacker technique and do not relate to fileless execution, which evades signature-based detection entirely by living in memory. Expecting EDR to monitor update jobs as a fileless attack vector misidentifies a defensive maintenance task as malicious behavior.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.