Courseiva
Host-Based Analysis →mediumMultiple Choice

200-201 Host-Based Analysis Practice Question

An analyst finds a registry modification under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options'. What is the primary use of this registry key?

⚠ Common exam trap

The trap is assuming IFEO is a benign debugging-only feature; candidates forget that its debugger redirection is a well-known persistence mechanism, so they overlook the malicious potential and pick a logging or firewall answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To set a debugger that runs when the image is executed

The Image File Execution Options (IFEO) registry key is used to specify a debugger that launches when a particular executable is started. Attackers abuse this by setting a 'Debugger' value to a malicious binary, achieving persistence and execution hijacking. Legitimate use includes attaching debuggers to specific processes, but the primary security-relevant function is debugger redirection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To configure network firewall rules for the image

    Why it's wrong here

    Image File Execution Options stores per-image launch settings, not firewall rules, which live in Windows Firewall policy under the relevant profile keys. It is tempting because IFEO is a per-application configuration location, and it would be correct where an analyst needs to permit or block an application's network traffic.

  • ✓

    To set a debugger that runs when the image is executed

    Why this is correct

    Image File Execution Options supports a Debugger value that Windows launches instead of the named executable. Attackers abuse this for persistence by pointing the debugger at malicious code, so the key's legitimate purpose is specifying a debugger for the image.

  • ✗

    To change the file extension association for the image

    Why it's wrong here

    File extension associations are held under HKEY_CLASSES_ROOT and the Explorer FileExts keys, not Image File Execution Options, which configures per-image launch behaviour. It is tempting because IFEO is keyed by executable name, and it would be correct where changing which program opens a given file type.

  • ✗

    To log all execution of the image to the Event Log

    Why it's wrong here

    Image File Execution Options does not log image execution to the Event Log; it holds per-executable settings, notably Debugger values that redirect or hijack process launch. It is tempting because IFEO entries can be abused for persistence, and it would be correct where auditing process creation, which uses Security event 4688 instead.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.