Courseiva
Host-Based Analysis →mediumMultiple Select

200-201 Host-Based Analysis Practice Question

A security analyst is reviewing a Windows host for indicators of credential dumping. The analyst wants to identify artifacts that commonly indicate tools such as Mimikatz have been used on the system. Which two artifacts should the analyst look for? (Choose two.)

⚠ Common exam trap

The trap here is selecting generic or benign system artifacts like Sysmon driver presence or Defender updates, which are unrelated to the LSASS-access behavior that credential dumping produces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Event ID 4656 or 4663 referencing lsass.exe with unusual access rights

Credential dumping targets LSASS memory, so the most reliable host artifacts are security events showing unusual handle access to lsass.exe and the presence of a memory dump file such as lsass.dmp in a user-writable location. Together these indicate that a tool attempted to extract credentials from LSASS on the endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security Event ID 4656 or 4663 referencing lsass.exe with unusual access rights

    Why this is correct

    Security Event IDs 4656 and 4663 record handle requests and object access, and when they reference lsass.exe with rights such as PROCESS_VM_READ, they strongly suggest a tool attempted to read credential material from LSASS memory. This is a classic indicator of credential dumping activity on a Windows host.

  • ✗

    An increase in Windows Defender signature definition version numbers

    Why it's wrong here

    Updated Defender signatures reflect normal antivirus maintenance and are not an indicator of credential dumping. In fact, signature updates often occur automatically, so their version changes provide no evidence that LSASS memory was accessed or dumped by an attacker tool on the host.

  • ✗

    Presence of a driver named SysmonDrv.sys in the System32\drivers directory

    Why it's wrong here

    SysmonDrv.sys is the legitimate kernel driver installed by Microsoft Sysmon for enhanced event logging. Its presence indicates the host has Sysmon deployed for monitoring, not that credential dumping occurred, so it is not an indicator of Mimikatz-style activity.

  • ✗

    Event ID 4688 showing the launch of notepad.exe by the SYSTEM account

    Why it's wrong here

    Notepad launched by SYSTEM is unusual but is not a recognized credential-dumping indicator and could result from many benign automation scenarios. It does not specifically point to LSASS access or memory dumping, so it is too weak and ambiguous to select as an artifact of Mimikatz activity.

  • ✓

    Creation of a memory dump file such as lsass.dmp in a user-writable directory

    Why this is correct

    Tools like Mimikatz or procdump can create a dump of LSASS process memory, often saved as lsass.dmp or a similarly named file in a user-writable path. Finding such a dump outside the standard Windows minidump locations is a strong indicator that credential dumping was attempted.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.