200-201 Security Monitoring Practice Question
A security analyst is examining a suspicious executable found on a compromised host. The analyst runs the command 'strings malware.exe' and sees the string 'cmd.exe /c net user hacker P@ssw0rd /add'. What is the most likely intent of this command?
⚠ Common exam trap
Many exam-takers confuse the 'net user' command for account creation with group membership changes, which require 'net localgroup' instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new user account named 'hacker' with a specified password.
The command 'net user hacker P@ssw0rd /add' is a classic Windows command to create a new local user account. The '/add' switch is the key indicator of account creation. This technique is often used by attackers for persistence, allowing them to regain access even if other malware is removed. The other options describe different actions that would require different syntax or switches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the user 'hacker' to the local administrators group.
Why it's wrong here
Adding a user to a group requires the 'net localgroup administrators hacker /add' command, not 'net user'. The observed string uses 'net user', which manages user accounts directly. While an attacker might later add the user to a group, this specific command does not perform that action. Therefore, this is not the most likely intent.
- ✓
Create a new user account named 'hacker' with a specified password.
Why this is correct
The command 'net user hacker P@ssw0rd /add' is used to create a new local user account named 'hacker' with the password 'P@ssw0rd'. This is a common persistence technique used by attackers to maintain access to a compromised system. The '/add' switch explicitly adds the user, and the syntax matches the Windows net user command. This is the most likely intent based on the string.
- ✗
Modify the password of an existing user account named 'hacker'.
Why it's wrong here
To modify an existing user's password, the command would be 'net user hacker P@ssw0rd' without the '/add' switch. The presence of '/add' indicates creation of a new account, not modification. If the account already existed, the command would fail unless the '/add' is omitted. Therefore, this is not the correct interpretation of the observed string.
- ✗
Delete the user account named 'hacker'.
Why it's wrong here
Deleting a user account uses the '/delete' switch, as in 'net user hacker /delete'. The observed command uses '/add', which is the opposite action. The string clearly shows addition, not deletion. Thus, this option misinterprets the command's purpose and would not be the analyst's conclusion.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.