Courseiva
Security Monitoring →mediumMultiple Select

200-201 Security Monitoring Practice Question

A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)

⚠ Common exam trap

The trap here is treating any unusual endpoint or network event as supporting evidence, when only behaviors tied to destroying backups and mass-encrypting files actually align with ransomware staging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A spike in SMB write operations to many file shares from a single workstation account.

Pre-encryption ransomware activity typically includes destroying recovery options and then rapidly encrypting data. Volume shadow copy deletion removes local restore points, while a burst of SMB writes to many shares shows encryption spreading across network storage. Together they form a coherent pattern that corroborates the suspicious PowerShell execution far better than routine DNS, update, or DHCP events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A spike in SMB write operations to many file shares from a single workstation account.

    Why this is correct

    Rapid, widespread writes to numerous network file shares from one account is consistent with a ransomware binary encrypting shared data after initial execution. This pattern distinguishes encryption activity from normal user file access, which is typically limited in scope. Combined with suspicious script execution, it provides strong corroboration of an active or imminent ransomware incident.

  • ✗

    A DHCP lease renewal for the workstation recorded by the local DHCP server.

    Why it's wrong here

    DHCP lease renewals occur automatically at regular intervals for nearly every host and carry no information about malicious intent. They cannot indicate ransomware preparation because they reflect routine network configuration rather than attacker behavior. Relying on lease events would produce noise in the investigation and distract from the meaningful indicators of encryption staging.

  • ✓

    Volume shadow copy deletion events recorded in Windows event logs.

    Why this is correct

    Ransomware operators commonly delete volume shadow copies to prevent victims from restoring encrypted files without paying. Observing shadow copy deletion shortly after suspicious script execution is a well-known pre-encryption behavior. This event strongly supports the hypothesis because it indicates deliberate preparation to remove recovery options before the encryption stage begins.

  • ✗

    An increase in DNS queries for known advertising domains from the workstation.

    Why it's wrong here

    Advertising domain queries are common background noise from browsers and applications and have no established relationship to ransomware preparation. While they might indicate unwanted software, they do not support a pre-encryption hypothesis. Including this finding would dilute the investigation and could lead the analyst to misclassify routine web activity as malicious staging behavior.

  • ✗

    Successful Windows Update installations completing on the workstation overnight.

    Why it's wrong here

    Completed Windows Updates indicate normal patching activity and are not associated with ransomware staging. If anything, timely patching reduces ransomware risk. Treating update events as supporting evidence would be a false positive that wastes analyst time and could obscure the genuinely suspicious behaviors, such as shadow copy deletion and mass file writes.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.