Courseiva
Host-Based Analysis →mediumMultiple Select

200-201 Host-Based Analysis Practice Question

A threat hunter is examining a Linux web server that is suspected of being compromised. The hunter wants to identify suspicious processes that may be communicating with external command-and-control infrastructure and to understand what files those processes have open. Which TWO artifacts or commands should the hunter use to accomplish these goals? (Choose two.)

⚠ Common exam trap

The trap here is gravitating toward log files like /var/log/secure or cron because they are familiar, when the scenario asks specifically about live process network and file-descriptor visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run 'ss -tunap' to enumerate listening and established sockets with their owning processes

Mapping C2 traffic and open files on Linux requires live process-to-socket visibility. The ss command with -tunap enumerates sockets together with owning processes, exposing established outbound connections. The /proc filesystem complements this by exposing per-process socket inodes and open file descriptors, letting the hunter pivot from a suspicious PID to the exact files and connections it holds. Together they reveal both the communication channel and the process context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review /var/log/secure for failed authentication attempts

    Why it's wrong here

    /var/log/secure (or /var/log/auth.log on Debian-based systems) records authentication events such as SSH logins and sudo use. It can show how an attacker gained access, but it does not reveal which processes are currently communicating externally or what files they have open, so it does not satisfy the hunter's stated objectives of mapping C2 traffic and open file handles.

  • ✓

    Run 'ss -tunap' to enumerate listening and established sockets with their owning processes

    Why this is correct

    The ss utility with -tunap lists TCP, UDP, and Unix sockets, including established connections and the process name and PID that owns each socket. This directly exposes outbound connections to external addresses and identifies the responsible process, which is precisely what the hunter needs to spot C2 communication on the compromised web server.

  • ✓

    Inspect /proc/<pid>/net/tcp and /proc/<pid>/fd to map network sockets and open file descriptors for each process

    Why this is correct

    The /proc filesystem exposes per-process network namespace information under /proc/<pid>/net/tcp and lists open file descriptors, including sockets symlinked as socket:[inode], under /proc/<pid>/fd. Correlating these lets the hunter tie a suspicious PID to an established connection and to the files or sockets it holds open, which is exactly the visibility needed for C2 triage.

  • ✗

    Parse the wtmp and btmp binary logs with the 'last' command

    Why it's wrong here

    The wtmp and btmp files record successful and failed login sessions respectively and are read with last and lastb. They are valuable for establishing an access timeline, but they contain no process-level network or file-descriptor information. They cannot identify a running process that is talking to a remote server, so they fall outside the hunter's objectives.

  • ✗

    Examine /etc/crontab for scheduled jobs

    Why it's wrong here

    /etc/crontab and the cron directories reveal scheduled tasks that could represent persistence, but they do not show live network connections or open file descriptors. A malicious cron entry might explain how malware restarts, yet it cannot tell the hunter which process is currently beaconing outbound, so it does not meet the requirement.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.