mediumMultiple Choice
200-201 Practice Question: A security analyst is investigating a host that…
A security analyst is investigating a host that is suspected of being used as a pivot point in a network intrusion. The analyst needs to identify which process initiated an outbound connection to a known malicious IP address. Which host-based analysis approach should the analyst use to correlate the network connection to the specific process?
⚠ Common exam trap
Cisco often tests the distinction between network-level logs (firewall logs) and host-level process-to-connection correlation, and the trap here is that candidates may choose 'Get-NetTCPConnection' (Option D) because it lists connections, but they overlook that it does not show the associated process executable without additional scripting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'netstat -b' on the Windows host to display active connections with the associated process executable.
Running 'netstat -b' on a Windows host displays active TCP connections along with the executable name of the process that created each connection. This directly correlates the outbound connection to the malicious IP with the specific process, which is exactly what the analyst needs to identify the pivot point.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run 'netstat -b' on the Windows host to display active connections with the associated process executable.
Why this is correct
netstat -b maps each active connection to the owning executable on Windows, directly correlating the outbound session to the malicious IP with the process that opened it. This identifies the pivot tool without packet capture.
- ✗
Examine the Windows Firewall log to see the source and destination IP addresses and ports for outbound traffic.
Why it's wrong here
Windows Firewall logs capture source and destination IP addresses and ports but never record the originating process name or PID, so no process correlation is possible. It is tempting because it shows outbound traffic directly, and would be correct for identifying which ports and remote hosts were contacted.
- ✗
Review Windows Security Event Log for Event ID 4688 (Process Creation) for the timeline of process starts.
Why it's wrong here
Event ID 4688 records process creation timestamps but contains no network connection data, so it cannot tie a process to the malicious IP. It is tempting for building a process-start timeline, and would be correct when correlating suspicious process execution against other logged events.
- ✗
Use PowerShell cmdlet 'Get-NetTCPConnection' to list current TCP connections and their states.
Why it's wrong here
Get-NetTCPConnection provides connection details but lacks the owning process information without additional options.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.