Courseiva
Host-Based Analysis →hardMultiple Choice

200-201 Host-Based Analysis Practice Question

A security analyst is examining a Linux server that is suspected of being compromised. The analyst runs `ls -l /proc/<PID>/exe` for a suspicious process and sees that the symbolic link points to `/tmp/.hidden/update` but the file no longer exists on disk. Which conclusion is most accurate?

⚠ Common exam trap

The trap here is interpreting a broken /proc/<PID>/exe symlink as evidence that the process is a zombie or kernel thread, when it actually indicates a deleted executable still running from memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The executable file was deleted while the process is still running.

On Linux, the /proc/<PID>/exe symlink points to the executable file. If that file is deleted while the process is running, the symlink remains but the target path is marked as deleted, and the file is no longer accessible via the filesystem. This is a known malware tactic to hinder forensic analysis. The analyst should copy /proc/<PID>/exe to preserve the binary before the process terminates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process is a kernel thread and does not have an executable on disk.

    Why it's wrong here

    Kernel threads are created by the kernel and typically have no user-space executable; their /proc/<PID>/exe link is usually absent or points to nothing. However, the presence of a symlink pointing to a user-space path like /tmp/.hidden/update indicates a user-space process, not a kernel thread. The broken link is due to file deletion, not kernel thread status.

  • ✗

    The process is running from a memory-mapped file and has no on-disk executable.

    Why it's wrong here

    While it is possible for a process to execute from a memory-mapped file, the /proc/<PID>/exe symlink would still typically point to a file path, often with ' (deleted)' if unlinked. The absence of the file on disk does not by itself prove memory-only execution; the broken symlink specifically indicates the original file was deleted after execution started.

  • ✗

    The process is a zombie and has already terminated.

    Why it's wrong here

    A zombie process has completed execution but still has an entry in the process table because its parent has not read its exit status. Its /proc/<PID>/exe link would typically be absent or broken, but the process would not be actively running. In this scenario, the process is still present with a valid PID, and the broken exe link indicates a deleted executable, not a zombie state.

  • ✓

    The executable file was deleted while the process is still running.

    Why this is correct

    On Linux, when an executable is deleted while a process is running, the /proc/<PID>/exe symlink still exists but points to the original path with a ' (deleted)' suffix, and the file is no longer visible on disk. This is a common malware technique to hide the binary while keeping it running. The analyst can recover the binary from /proc/<PID>/exe before the process exits.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.