200-201 Security Monitoring Practice Question
A SOC analyst is correlating events in the SIEM after an alert fired for suspicious PowerShell execution on a workstation. The analyst wants to identify additional evidence that would support a ransomware pre-encryption hypothesis. Which two telemetry findings would most strongly support that hypothesis? (Choose two.)
⚠ Common exam trap
The trap here is treating any unusual endpoint or network event as supporting evidence, when only behaviors tied to destroying backups and mass-encrypting files actually align with ransomware staging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A spike in SMB write operations to many file shares from a single workstation account.
Pre-encryption ransomware activity typically includes destroying recovery options and then rapidly encrypting data. Volume shadow copy deletion removes local restore points, while a burst of SMB writes to many shares shows encryption spreading across network storage. Together they form a coherent pattern that corroborates the suspicious PowerShell execution far better than routine DNS, update, or DHCP events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A spike in SMB write operations to many file shares from a single workstation account.
Why this is correct
Rapid, widespread writes to numerous network file shares from one account is consistent with a ransomware binary encrypting shared data after initial execution. This pattern distinguishes encryption activity from normal user file access, which is typically limited in scope. Combined with suspicious script execution, it provides strong corroboration of an active or imminent ransomware incident.
- ✗
A DHCP lease renewal for the workstation recorded by the local DHCP server.
Why it's wrong here
DHCP lease renewals occur automatically at regular intervals for nearly every host and carry no information about malicious intent. They cannot indicate ransomware preparation because they reflect routine network configuration rather than attacker behavior. Relying on lease events would produce noise in the investigation and distract from the meaningful indicators of encryption staging.
- ✓
Volume shadow copy deletion events recorded in Windows event logs.
Why this is correct
Ransomware operators commonly delete volume shadow copies to prevent victims from restoring encrypted files without paying. Observing shadow copy deletion shortly after suspicious script execution is a well-known pre-encryption behavior. This event strongly supports the hypothesis because it indicates deliberate preparation to remove recovery options before the encryption stage begins.
- ✗
An increase in DNS queries for known advertising domains from the workstation.
Why it's wrong here
Advertising domain queries are common background noise from browsers and applications and have no established relationship to ransomware preparation. While they might indicate unwanted software, they do not support a pre-encryption hypothesis. Including this finding would dilute the investigation and could lead the analyst to misclassify routine web activity as malicious staging behavior.
- ✗
Successful Windows Update installations completing on the workstation overnight.
Why it's wrong here
Completed Windows Updates indicate normal patching activity and are not associated with ransomware staging. If anything, timely patching reduces ransomware risk. Treating update events as supporting evidence would be a false positive that wastes analyst time and could obscure the genuinely suspicious behaviors, such as shadow copy deletion and mass file writes.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.