Courseiva
Host-Based Analysis →mediumMultiple Choice

200-201 Host-Based Analysis Practice Question

An analyst is examining a Windows system for evidence of malware that maintains persistence by modifying the Image File Execution Options (IFEO) registry key. Which of the following best describes how this technique works?

⚠ Common exam trap

Watch out — candidates often confuse IFEO with other persistence mechanisms like services or Winlogon; IFEO specifically uses the Debugger value to redirect execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The malware sets the 'Debugger' value for a legitimate process, causing the debugger to execute instead of the intended process.

Image File Execution Options (IFEO) is a registry key that allows setting a debugger for a specific executable. Malware abuses this by setting the Debugger value to its own binary, so when the targeted process is launched, the malicious debugger runs instead. This provides persistence and can be used to hijack trusted processes, making detection challenging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The malware adds a new service that runs under the context of the SYSTEM account.

    Why it's wrong here

    Adding a new service is a separate persistence technique, often using the Service Control Manager or registry keys like HKLM\SYSTEM\CurrentControlSet\Services. IFEO does not involve creating services; it hijacks the execution of existing processes via the Debugger value. This option confuses two distinct persistence methods.

  • ✓

    The malware sets the 'Debugger' value for a legitimate process, causing the debugger to execute instead of the intended process.

    Why this is correct

    IFEO allows developers to attach a debugger to a process. Malware can abuse this by setting the 'Debugger' value under the IFEO key for a legitimate process (e.g., notepad.exe) to point to a malicious executable. When the legitimate process is launched, the malicious 'debugger' runs instead, achieving persistence and potentially privilege escalation.

  • ✗

    The malware creates a shortcut in the Startup folder to launch automatically.

    Why it's wrong here

    Startup folder shortcuts are a simple persistence method, but they do not involve IFEO or the registry. IFEO is a registry-based technique that affects process creation. This option describes a file system-based persistence mechanism, which is not related to the scenario's focus on IFEO.

  • ✗

    The malware modifies the 'Shell' value in the Winlogon registry key to execute on user logon.

    Why it's wrong here

    Modifying the Winlogon Shell value is a classic persistence technique, but it is unrelated to IFEO. IFEO specifically targets process execution by setting a debugger. The Winlogon Shell value replaces the user's shell (typically explorer.exe), which is a different mechanism. This option describes a different registry-based persistence method.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.