200-201 Host-Based Analysis Practice Question
An analyst finds a registry modification under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options'. What is the primary use of this registry key?
⚠ Common exam trap
The trap is assuming IFEO is a benign debugging-only feature; candidates forget that its debugger redirection is a well-known persistence mechanism, so they overlook the malicious potential and pick a logging or firewall answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To set a debugger that runs when the image is executed
The Image File Execution Options (IFEO) registry key is used to specify a debugger that launches when a particular executable is started. Attackers abuse this by setting a 'Debugger' value to a malicious binary, achieving persistence and execution hijacking. Legitimate use includes attaching debuggers to specific processes, but the primary security-relevant function is debugger redirection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To configure network firewall rules for the image
Why it's wrong here
Image File Execution Options stores per-image launch settings, not firewall rules, which live in Windows Firewall policy under the relevant profile keys. It is tempting because IFEO is a per-application configuration location, and it would be correct where an analyst needs to permit or block an application's network traffic.
- ✓
To set a debugger that runs when the image is executed
Why this is correct
Image File Execution Options supports a Debugger value that Windows launches instead of the named executable. Attackers abuse this for persistence by pointing the debugger at malicious code, so the key's legitimate purpose is specifying a debugger for the image.
- ✗
To change the file extension association for the image
Why it's wrong here
File extension associations are held under HKEY_CLASSES_ROOT and the Explorer FileExts keys, not Image File Execution Options, which configures per-image launch behaviour. It is tempting because IFEO is keyed by executable name, and it would be correct where changing which program opens a given file type.
- ✗
To log all execution of the image to the Event Log
Why it's wrong here
Image File Execution Options does not log image execution to the Event Log; it holds per-executable settings, notably Debugger values that redirect or hijack process launch. It is tempting because IFEO entries can be abused for persistence, and it would be correct where auditing process creation, which uses Security event 4688 instead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.