easyMultiple Choice
Incident Response for Host-Based Analysis: Step-by-Step Guide
A SOC analyst is investigating a suspicious file on a Windows host. The file hash matches a known malware variant in a threat intelligence feed. What is the next best step for host-based analysis?
⚠ Common exam trap
Cisco often tests the distinction between host-based analysis (focusing on local artifacts like persistence, processes, and registry) and network-based containment (like disabling adapters), so candidates mistakenly choose network isolation steps when the question explicitly asks for host-based analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check for persistence mechanisms such as registry Run keys or scheduled tasks
After confirming a file hash matches a known malware variant, the immediate priority for host-based analysis is to determine how the malware maintains persistence on the system. Persistence mechanisms such as Registry Run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) or scheduled tasks (via schtasks.exe) allow malware to survive reboots and re-establish execution. Identifying these artifacts is critical for containment and eradication, as it reveals the malware's foothold and prevents re-infection after removal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the host
Why it's wrong here
A full antivirus scan detects and remediates files on disk, but it does not reveal the malware's runtime behaviour, persistence mechanisms or network callbacks on the already-compromised host. It is tempting because antivirus is the standard first response to a known signature match, and would be correct for broad endpoint hygiene rather than targeted incident analysis.
- ✗
Disable the network adapter to prevent further communication
Why it's wrong here
Disabling the adapter preserves the host but severs containment telemetry and any live command-and-control observation; it also does not isolate the file itself. Network isolation is the move when active exfiltration is confirmed and the priority is stopping outbound traffic immediately.
- ✓
Check for persistence mechanisms such as registry Run keys or scheduled tasks
Why this is correct
A confirmed hash match establishes the file is malicious, so analysis shifts from identification to impact. Persistence mechanisms such as Run keys and scheduled tasks reveal how the malware survives reboots, satisfying the host-based scope by exposing the adversary's foothold.
- ✗
Reboot the host to clear the malware from memory
Why it's wrong here
Rebooting destroys volatile evidence — running processes, memory-resident code, network connections — before collection, and does not remove persistent malware from disk. Memory capture and forensic imaging precede any restart; rebooting is a remediation step taken after evidence is preserved.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.