200-201 Host-Based Analysis Practice Question
A SOC analyst is reviewing a Windows 10 endpoint that is suspected of being compromised by malware that hides its network connections. The analyst runs 'netstat -anob' on the live system but does not see any suspicious outbound connections. Which Windows artifact should the analyst examine next to identify network connections that may have been hidden from the live API?
⚠ Common exam trap
The trap here is assuming that if netstat shows nothing suspicious, the host made no suspicious network connections, when API-hooking malware can hide from live queries while SRUM still logs the traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SRUM database (SRUDB.dat) parsed with a tool such as srum-dump
SRUM maintains a rolling record of per-application resource usage, including bytes sent and received and network interface activity, in the SRUDB.dat ESE database. Because it is populated by the SRUM service rather than by the APIs malware commonly hooks to hide from netstat or GetTcpTable, it can surface external communications that live commands miss. Parsing SRUM therefore gives the analyst network evidence the live system concealed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The SRUM database (SRUDB.dat) parsed with a tool such as srum-dump
Why this is correct
SRUM (System Resource Usage Monitor) records per-application network usage and bytes sent/received over time, stored in SRUDB.dat. Malware that hooks live APIs to hide from netstat still generates SRUM entries because the ESE database is populated by the ESE-based SRUM service, not by the APIs the malware hooks. Parsing it can reveal a process that communicated externally even when live tooling shows nothing.
- ✗
The Amcache.hve registry hive parsed with AmcacheParser
Why it's wrong here
Amcache.hve tracks program installation, execution, and SHA-1 hashes of executables, which is useful for identifying what ran on the host. It does not log network endpoints, connection state, or per-process byte counts. In this scenario the analyst already suspects the process ran; the gap is network telemetry, which Amcache cannot fill.
- ✗
The ShimCache (AppCompatCache) entries in the SYSTEM hive
Why it's wrong here
ShimCache, stored in the SYSTEM hive under AppCompatCache, records executables that were present or executed to support application compatibility shimming. It provides file paths and sometimes timestamps, not network connection details. Relying on it here would not reveal any hidden socket, so it does not resolve the analyst's problem.
- ✗
The Windows Prefetch files parsed with PECmd
Why it's wrong here
Prefetch files record executable load and file-access patterns to speed up application launch; they contain timestamps and referenced file paths, but not network connection tuples or byte counts. PECmd can show that a suspicious binary ran, yet it cannot tell the analyst which remote IP or port that binary contacted, so it does not address the missing network-connection evidence in this scenario.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.