Courseiva
Host-Based Analysis →hardMultiple Select

200-201 Host-Based Analysis Practice Question

An analyst is analyzing a Linux system that may have been compromised. Which THREE artifacts would provide evidence of attacker activity? (Choose three.)

⚠ Common exam trap

The trap is confusing general system files with forensic artifacts; candidates might select /etc/passwd because it relates to user accounts, but it is not as indicative of active attacker activity as the other three.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/var/spool/cron/crontabs/

Option B, /var/spool/cron/crontabs/, is correct because attackers commonly establish persistence by adding malicious cron jobs here (per-user crontabs on Debian/Ubuntu systems), so unexpected entries provide direct evidence of attacker activity. Option D, /var/log/auth.log, is correct because it records authentication events such as SSH logins, sudo usage, and failed/successful password attempts, which can reveal unauthorized access or brute-force activity. Option E, /home/user/.bash_history, is correct because it preserves the commands a user (or an attacker operating under that account) executed, often exposing reconnaissance, privilege escalation, or data exfiltration commands. Option A, /proc/cpuinfo, is not relevant because it only exposes CPU hardware details from the kernel and contains no record of user or attacker actions. Option C, /etc/passwd, is not the best evidence of activity because it is a static account database listing users; while tampering (e.g., a rogue UID 0 account) could be suspicious, the file itself does not log activity, and the question asks for artifacts evidencing attacker activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /proc/cpuinfo

    Why it's wrong here

    /proc/cpuinfo exposes processor model, cores, and flags — static hardware data regenerated at boot, with no persistence or timestamps. It is tempting because /proc entries are volatile and attacker-touchable, and cpuinfo would be relevant when profiling host capability during malware analysis rather than proving compromise.

  • ✓

    /var/spool/cron/crontabs/

    Why this is correct

    The /var/spool/cron/crontabs/ directory holds per-user cron schedules on Linux, so any malicious job an attacker added for persistence appears here as a readable file. This directly satisfies the stem's requirement for evidence of attacker activity, revealing scheduled commands that re-establish access or execute payloads after reboot.

  • ✗

    /etc/passwd

    Why it's wrong here

    /etc/passwd holds local account definitions, not authentication events; a modified entry shows account tampering but no login, process, or command history. It is tempting because attackers do add rogue accounts, and passwd would be the right artefact when auditing unauthorised local user creation.

  • ✓

    /var/log/auth.log

    Why this is correct

    This file records authentication events, including successful and failed logins, sudo usage and session openings. It satisfies the Linux artefact requirement by exposing brute-force attempts, credential abuse or unauthorised privilege escalation on the compromised host.

  • ✓

    /home/user/.bash_history

    Why this is correct

    Shell command history records commands executed under that account, revealing attacker reconnaissance, privilege escalation attempts or data exfiltration. It satisfies the Linux artefact requirement by exposing post-compromise activity tied to the compromised user's interactive session.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.