200-201 Host-Based Analysis Practice Question
A security analyst is reviewing a Windows host for indicators of credential dumping. The analyst wants to identify artifacts that commonly indicate tools such as Mimikatz have been used on the system. Which two artifacts should the analyst look for? (Choose two.)
⚠ Common exam trap
The trap here is selecting generic or benign system artifacts like Sysmon driver presence or Defender updates, which are unrelated to the LSASS-access behavior that credential dumping produces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Event ID 4656 or 4663 referencing lsass.exe with unusual access rights
Credential dumping targets LSASS memory, so the most reliable host artifacts are security events showing unusual handle access to lsass.exe and the presence of a memory dump file such as lsass.dmp in a user-writable location. Together these indicate that a tool attempted to extract credentials from LSASS on the endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security Event ID 4656 or 4663 referencing lsass.exe with unusual access rights
Why this is correct
Security Event IDs 4656 and 4663 record handle requests and object access, and when they reference lsass.exe with rights such as PROCESS_VM_READ, they strongly suggest a tool attempted to read credential material from LSASS memory. This is a classic indicator of credential dumping activity on a Windows host.
- ✗
An increase in Windows Defender signature definition version numbers
Why it's wrong here
Updated Defender signatures reflect normal antivirus maintenance and are not an indicator of credential dumping. In fact, signature updates often occur automatically, so their version changes provide no evidence that LSASS memory was accessed or dumped by an attacker tool on the host.
- ✗
Presence of a driver named SysmonDrv.sys in the System32\drivers directory
Why it's wrong here
SysmonDrv.sys is the legitimate kernel driver installed by Microsoft Sysmon for enhanced event logging. Its presence indicates the host has Sysmon deployed for monitoring, not that credential dumping occurred, so it is not an indicator of Mimikatz-style activity.
- ✗
Event ID 4688 showing the launch of notepad.exe by the SYSTEM account
Why it's wrong here
Notepad launched by SYSTEM is unusual but is not a recognized credential-dumping indicator and could result from many benign automation scenarios. It does not specifically point to LSASS access or memory dumping, so it is too weak and ambiguous to select as an artifact of Mimikatz activity.
- ✓
Creation of a memory dump file such as lsass.dmp in a user-writable directory
Why this is correct
Tools like Mimikatz or procdump can create a dump of LSASS process memory, often saved as lsass.dmp or a similarly named file in a user-writable path. Finding such a dump outside the standard Windows minidump locations is a strong indicator that credential dumping was attempted.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.