200-201 Host-Based Analysis Practice Question
A security analyst is investigating a Linux server that was compromised. The attacker used a rootkit to hide processes and files. The analyst runs 'lsmod' and notices a kernel module named 'hideproc' that is not recognized. Which command should the analyst use to determine the module's file path and potentially identify the rootkit?
⚠ Common exam trap
Watch out — candidates often confuse listing loaded modules with obtaining detailed module information, such as the file path, which requires modinfo.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
modinfo hideproc
The analyst needs to find the file path of the suspicious kernel module to analyze or remove it. The modinfo command provides detailed information about a module, including its filename and location. This is the correct tool for identifying where the rootkit module resides on disk, enabling further forensic analysis or cleanup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
lsmod | grep hideproc
Why it's wrong here
lsmod lists currently loaded modules but only shows the module name, size, and usage count. It does not provide the file path or additional metadata. While it confirms the module is loaded, it does not help locate the file on disk.
- ✗
dmesg | grep hideproc
Why it's wrong here
dmesg displays kernel ring buffer messages, which may show that the module was loaded but typically does not include the full file path. It could provide context about loading errors or warnings but is not the primary tool for module file path discovery.
- ✗
rmmod hideproc
Why it's wrong here
rmmod attempts to remove a loaded kernel module. While this might be part of remediation, it does not provide information about the module's file path or help identify the rootkit's location. Moreover, removing a module without understanding it could destabilize the system.
- ✓
modinfo hideproc
Why this is correct
modinfo displays information about a kernel module, including its filename, description, author, and license. Running 'modinfo hideproc' will show the full path to the module file, which can then be analyzed or removed. This directly helps identify the rootkit's location.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.