200-201 Host-Based Analysis Practice Question
A security analyst is examining a Windows 10 endpoint that is suspected of being infected with malware. The analyst runs 'Get-WinEvent -LogName Security | Where-Object {$_.Id -eq 4688}' and notices that a process named 'cmd.exe' was launched with the command line 'cmd /c vssadmin.exe delete shadows /all /quiet'. Which type of attack does this command indicate?
⚠ Common exam trap
The trap here is misinterpreting the command as a benign administrative action, ignoring the context of a suspected infection and the destructive nature of deleting all shadow copies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware deleting volume shadow copies to prevent recovery
The command 'vssadmin delete shadows /all /quiet' is a hallmark of ransomware, used to eliminate backup copies before encrypting files. It is often executed via cmd.exe in scripts. Detecting this command in process creation logs is a high-fidelity indicator of ransomware activity, allowing for immediate response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A legitimate backup operation removing old shadow copies
Why it's wrong here
Legitimate backup software typically manages shadow copies through APIs or scheduled tasks, not by launching cmd.exe with this exact command. The /quiet flag suppresses prompts, which is unusual for interactive administration. This behavior is more indicative of malicious intent than routine backup maintenance.
- ✗
A system administrator troubleshooting disk space issues
Why it's wrong here
While deleting shadow copies frees disk space, an administrator would likely use the Volume Shadow Copy Service interface or a script with logging. The silent deletion of all shadow copies is extreme and not a typical troubleshooting step. This action is destructive and aligns with ransomware tactics.
- ✗
A malware family using shadow copy deletion for anti-forensics
Why it's wrong here
Although deleting shadow copies can hinder forensics, the primary motivation in ransomware is to prevent recovery. Other malware might delete logs or timestamps for anti-forensics, but this specific command is strongly associated with ransomware. The scenario points to ransomware due to the command's known use in encryption campaigns.
- ✓
Ransomware deleting volume shadow copies to prevent recovery
Why this is correct
The command 'vssadmin delete shadows /all /quiet' is a known technique used by ransomware to delete shadow copies, making it impossible to restore encrypted files. This is a common precursor to encryption. The use of cmd.exe to execute it is typical for scripted attacks, indicating ransomware activity.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.