Courseiva
Host-Based Analysis →mediumMultiple Select

200-201 Host-Based Analysis Practice Question

A security analyst is investigating a Linux host for signs of compromise. The analyst runs `ps aux` and notices a process named `kworker` with a high CPU usage. The analyst suspects this may be a masquerading malware process. Which TWO commands should the analyst use to verify whether this process is legitimate or malicious? (Choose two.)

⚠ Common exam trap

The trap here is relying on process names alone, which can be spoofed, instead of verifying the underlying executable and command line via /proc.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

`ls -l /proc/<PID>/exe` to check the executable path

Legitimate kernel worker threads (kworker) have no user-space executable and an empty cmdline. Checking /proc/<PID>/exe reveals if the process points to a real binary, and /proc/<PID>/cmdline shows the command line. If either indicates a user-space path or non-empty arguments, the process is likely masquerading. These two checks together provide strong evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    `ls -l /proc/<PID>/exe` to check the executable path

    Why this is correct

    The /proc/<PID>/exe symlink points to the actual executable file. For a legitimate kernel worker, this link is typically absent or points to nothing because kernel threads have no user-space executable. If it points to a file in /tmp or another suspicious location, it indicates a masquerading process. This is a quick and effective check.

  • ✗

    `df -h` to check disk usage

    Why it's wrong here

    df -h displays filesystem disk space usage. It provides no information about process identity, executable path, or command line. It is irrelevant to determining whether a process is a legitimate kernel worker or malware. Therefore, it should not be used for this purpose.

  • ✗

    `netstat -tulpn` to list all listening ports

    Why it's wrong here

    netstat shows network connections and listening ports, which can indicate if the process is communicating over the network. However, it does not directly verify whether the process is a legitimate kernel thread or a masquerading binary. While useful for network analysis, it does not provide the process identity evidence needed here.

  • ✗

    `top -c` to view the process list with command lines

    Why it's wrong here

    top -c shows running processes with their command lines, but it may not display the full path or distinguish kernel threads. It is similar to ps and does not provide the definitive executable path or empty cmdline check that /proc/<PID>/exe and /proc/<PID>/cmdline offer. It is less precise for this verification.

  • ✓

    `cat /proc/<PID>/cmdline` to view the command line arguments

    Why this is correct

    The /proc/<PID>/cmdline file contains the command line used to start the process, with arguments separated by null bytes. A legitimate kworker kernel thread has an empty cmdline, while a malicious process masquerading as kworker may show a path and arguments. This helps distinguish kernel threads from user-space impostors.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.