200-201 Host-Based Analysis Practice Question
An analyst is examining a Windows system for evidence of malware that maintains persistence by modifying the Image File Execution Options (IFEO) registry key. Which of the following best describes how this technique works?
⚠ Common exam trap
Watch out — candidates often confuse IFEO with other persistence mechanisms like services or Winlogon; IFEO specifically uses the Debugger value to redirect execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The malware sets the 'Debugger' value for a legitimate process, causing the debugger to execute instead of the intended process.
Image File Execution Options (IFEO) is a registry key that allows setting a debugger for a specific executable. Malware abuses this by setting the Debugger value to its own binary, so when the targeted process is launched, the malicious debugger runs instead. This provides persistence and can be used to hijack trusted processes, making detection challenging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The malware adds a new service that runs under the context of the SYSTEM account.
Why it's wrong here
Adding a new service is a separate persistence technique, often using the Service Control Manager or registry keys like HKLM\SYSTEM\CurrentControlSet\Services. IFEO does not involve creating services; it hijacks the execution of existing processes via the Debugger value. This option confuses two distinct persistence methods.
- ✓
The malware sets the 'Debugger' value for a legitimate process, causing the debugger to execute instead of the intended process.
Why this is correct
IFEO allows developers to attach a debugger to a process. Malware can abuse this by setting the 'Debugger' value under the IFEO key for a legitimate process (e.g., notepad.exe) to point to a malicious executable. When the legitimate process is launched, the malicious 'debugger' runs instead, achieving persistence and potentially privilege escalation.
- ✗
The malware creates a shortcut in the Startup folder to launch automatically.
Why it's wrong here
Startup folder shortcuts are a simple persistence method, but they do not involve IFEO or the registry. IFEO is a registry-based technique that affects process creation. This option describes a file system-based persistence mechanism, which is not related to the scenario's focus on IFEO.
- ✗
The malware modifies the 'Shell' value in the Winlogon registry key to execute on user logon.
Why it's wrong here
Modifying the Winlogon Shell value is a classic persistence technique, but it is unrelated to IFEO. IFEO specifically targets process execution by setting a debugger. The Winlogon Shell value replaces the user's shell (typically explorer.exe), which is a different mechanism. This option describes a different registry-based persistence method.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.