200-201 Security Monitoring Practice Question
A security analyst is reviewing Sysmon telemetry from a workstation that may be compromised. Which TWO event types should the analyst correlate first to identify suspicious process execution and persistence? (Choose two.)
⚠ Common exam trap
The trap here is selecting events by general security interest, such as DNS or network connections, instead of matching the event types to the specific investigative goals of execution and persistence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event ID 1, Process Create, which records the image path, command line, and parent process.
Process Create establishes what ran, from where, with which arguments, and under which parent, while Registry Value Set reveals the persistence the process installed. Correlating the two links a specific executable to a specific autorun or service entry, which is the fastest way to confirm suspicious execution and durable persistence on a Windows endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Event ID 1, Process Create, which records the image path, command line, and parent process.
Why this is correct
Process Create captures the executable path, full command line, user, hashes, and parent process identifier, which together reveal suspicious invocations such as encoded PowerShell or an unexpected child of a document reader. It is the primary Sysmon event for identifying malicious execution and building process lineage during triage, so it belongs in the first correlation step.
- ✗
Event ID 22, DNS Query, which records name resolution requests made by processes.
Why it's wrong here
DNS Query events expose command-and-control or payload staging domains, which is valuable for network-level detection. However, the stem asks specifically about process execution and persistence, and DNS telemetry does not show how a process was launched or what registry or startup mechanism it installed. It is better used after execution and persistence are established.
- ✓
Event ID 13, Registry Value Set, which records registry modifications including value names and data.
Why this is correct
Registry Value Set captures writes to registry keys and values, which is how many persistence mechanisms are installed, such as Run keys, services, and scheduled task definitions. Correlating it with process creation shows which executable established persistence and what it wrote, making it one of the two highest-value events for this investigation.
- ✗
Event ID 3, Network Connection, which records TCP and UDP connection attempts by processes.
Why it's wrong here
Network Connection events map processes to remote endpoints and are excellent for confirming beaconing or lateral movement. They complement execution analysis by tying a process identifier to a destination, but they do not reveal parent-child relationships or registry-based persistence. For the stated goal of identifying execution and persistence, they are secondary to process and registry telemetry.
- ✗
Event ID 11, File Create, which records file creation and overwrite operations with their paths.
Why it's wrong here
File Create is useful for spotting dropped payloads in temporary or startup directories, but on its own it does not show which process performed the write or how it was launched. It is a supporting data source rather than a primary one for establishing execution and persistence relationships, so it is not among the two events to correlate first.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.