200-201 Host-Based Analysis Practice Question
An analyst discovers a suspicious service on a Windows host. Which command can be used to query the status and details of services from the command line?
⚠ Common exam trap
The trap is confusing GUI tools (services.msc) or process-listing tools (tasklist /svc) with the actual CLI service-query command — candidates pick 'net start' because it's familiar, but it only lists running services, not their configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sc query
The 'sc query' command queries the Service Control Manager for the status of a specified service (or all services) directly from the command line, showing state (RUNNING/STOPPED), service type, and exit codes. It is the standard CLI tool for enumerating and inspecting Windows services during host-based forensic analysis. 'sc query type= service state= all' lists every service with its status, making it ideal for spotting suspicious entries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
services.msc
Why it's wrong here
services.msc launches the graphical Services console, which requires an interactive desktop session; the question specifies command-line querying. The analyst needs a CLI tool. services.msc is appropriate when working locally at a GUI and manually inspecting or reconfiguring service properties.
- ✗
net start
Why it's wrong here
net start without arguments enumerates running services only, omitting stopped services and configuration details such as start type and binary path. The analyst needs full status and details. net start is correct when starting a specific named service or confirming which services are currently running.
- ✓
sc query
Why this is correct
The sc query command interrogates the Service Control Manager directly, returning the service's current state (running, stopped, paused) plus configuration details such as start type and binary path. This satisfies the requirement to check status and details of a suspicious service from the command line without needing GUI tools.
- ✗
tasklist /svc
Why it's wrong here
tasklist /svc lists running processes and the services hosted inside each, mapping services to PIDs rather than reporting service configuration or start state. The analyst needs service status and details. tasklist suits identifying which process hosts a service during live triage.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.