200-201 Security Concepts Practice Question
An analyst is examining a suspicious executable recovered from a compromised host. Static analysis shows it is packed, and dynamic analysis in a sandbox reveals it creates a mutex, modifies registry Run keys, and attempts to connect to a hardcoded IP address on port 443. The file also contains a section with high entropy. Which characteristic most strongly suggests the file is packed or encrypted?
⚠ Common exam trap
The trap here is focusing on dynamic behaviors like persistence or C2, which are separate from the static structural clue of high entropy that indicates packing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A section with high entropy
High entropy in a section is a classic static indicator of packing or encryption, because compressed or encrypted data lacks the patterns of normal executable code. Packers use this to hide the original code and evade signature-based detection. The other observed behaviors are runtime actions related to persistence and command-and-control, not structural evidence of packing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A section with high entropy
Why this is correct
High entropy in a file section indicates compressed or encrypted data, which is typical of packed malware. Packers compress or encrypt the original code to evade signature detection, and the unpacking stub restores it at runtime. The high-entropy section is a strong static indicator that the executable is packed or encrypted.
- ✗
Connection to a hardcoded IP on port 443
Why it's wrong here
Connecting to a hardcoded IP on port 443 suggests command-and-control communication, often attempting to blend with HTTPS traffic. This is a network behavior indicator, not evidence of packing or encryption of the file itself. It does not describe the file's internal structure or entropy.
- ✗
Modification of registry Run keys
Why it's wrong here
Modifying Run keys is a persistence technique that causes the malware to execute at startup or logon. It is a behavioral indicator of persistence, not a structural sign of packing or encryption. This action would be observed during dynamic analysis regardless of whether the file is packed.
- ✗
Creation of a mutex
Why it's wrong here
A mutex is a synchronization object used to prevent multiple instances of malware from running simultaneously. Its presence indicates the malware may check for an existing infection, but it does not indicate packing or encryption. Mutex creation is behavioral and unrelated to the file's entropy or structure.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.