Courseiva
Host-Based Analysis →hardMultiple Choice

200-201 Host-Based Analysis Practice Question

A threat hunter is examining a Windows 10 host and wants to determine whether a suspicious executable was recently run by a user. The hunter knows that Windows records application execution history in the registry under the UserAssist key. Which location should the hunter inspect to find this data for the currently logged-on user?

⚠ Common exam trap

It's easy for candidates to confuse execution-history artifacts like UserAssist with autostart persistence keys like Run, which record configuration rather than a history of what actually ran.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count

UserAssist under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist stores per-user execution history for programs launched through Explorer. The Count subkey under each GUID contains ROT13-encoded values that include the program path and a run counter, letting the hunter confirm recent execution by the current user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    Why it's wrong here

    The Run key under HKCU is an autostart location that lists programs configured to launch at user logon. It shows persistence configuration rather than a historical record of what has already executed, so it cannot confirm whether the suspicious executable was recently run by the user.

  • ✗

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store

    Why it's wrong here

    The Compatibility Assistant Store key records applications that were flagged by the Program Compatibility Assistant when they failed or required compatibility shims. It captures a narrow set of compatibility-related executions, not the general Explorer-launched execution history that UserAssist provides.

  • ✓

    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count

    Why this is correct

    The UserAssist key under HKCU stores ROT13-encoded entries for programs launched through Windows Explorer, including the executable name and a run counter. Inspecting the Count subkey under the GUID path reveals execution history for the current user, which is exactly what the threat hunter needs to confirm recent execution.

  • ✗

    HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings

    Why it's wrong here

    The Background Activity Moderator (BAM) key under HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings tracks execution of background applications per user SID, but it is a system-wide key rather than a user-specific Explorer execution history. It is useful but not the UserAssist location the hunter is asked to inspect.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.