Courseiva
Host-Based Analysis →easyMultiple Choice

200-201 Host-Based Analysis Practice Question

A security analyst is reviewing a Windows workstation that is suspected of being infected with malware that establishes persistence. The analyst wants to check a location that is commonly used by malware to automatically start when a user logs on. Which of the following should the analyst examine?

⚠ Common exam trap

Many exam-takers confuse forensic artifacts that record execution, such as Prefetch, with actual auto-start extensibility points like the Startup folder that cause execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Startup folder for the current user

The Startup folder is a well-known user-level persistence location. Any program or shortcut placed there will execute automatically when the user logs on. Malware frequently uses this folder because it requires no administrative privileges and is easy to implement. Analysts should check both the per-user Startup folder and the all-users Startup folder for suspicious entries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Recycle Bin

    Why it's wrong here

    The Recycle Bin stores deleted files and folders, allowing users to restore them. It is not an auto-start location and does not execute anything on logon. While malware might hide files there, it would not achieve persistence through the Recycle Bin alone. Therefore, it is not the correct location to check for automatic startup.

  • ✗

    The Prefetch folder

    Why it's wrong here

    The Prefetch folder (C:\Windows\Prefetch) contains .pf files that record execution history and are used to speed up application launches. While useful for forensics to determine what ran, Prefetch entries do not cause programs to start automatically. Thus, it is not a persistence location.

  • ✗

    The Windows Defender quarantine folder

    Why it's wrong here

    The Windows Defender quarantine folder stores files that have been detected and quarantined by Windows Defender. These files are isolated and cannot execute. They are not used for persistence. Examining this folder might show past detections, but it does not reveal active persistence mechanisms.

  • ✓

    The Startup folder for the current user

    Why this is correct

    The Startup folder (e.g., %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) contains shortcuts and executables that run automatically when the user logs on. Malware often places a copy or shortcut here to maintain persistence. Checking this folder is a standard step in host-based analysis for user-level persistence.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.