Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

An analyst is examining a YARA rule that contains the condition: 'uint16(0) == 0x5a4d and filesize < 500KB'. What type of file is this rule targeting?

⚠ Common exam trap

Test-takers frequently confuse common file magic numbers; candidates might mistakenly associate 'MZ' with other file types or overlook that uint16(0) reads the first two bytes as a little-endian value, leading to incorrect identification of the file type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows executable files

The condition 'uint16(0) == 0x5a4d' checks the first two bytes of a file for the hexadecimal value 0x5a4d, which corresponds to the ASCII characters 'MZ'. This 'MZ' signature is the magic number for DOS/Windows executable files (e.g., .exe, .dll). The additional constraint 'filesize < 500KB' further narrows the rule to small Windows executables. Therefore, the rule targets Windows executable files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows executable files

    Why this is correct

    The uint16(0) == 0x5a4d check reads the MZ magic bytes at offset zero, the DOS header signature unique to Windows PE executables. The filesize constraint simply limits scanning to smaller binaries, confirming the rule targets Windows executable files.

  • ✗

    PDF files

    Why it's wrong here

    The uint16(0) == 0x5a4d condition matches the MZ magic bytes at offset zero of Windows PE executables, not the %PDF header that PDF files carry. YARA rules targeting PDFs would check for that specific header signature; this rule's filesize and magic-byte logic is written for portable executables.

  • ✗

    JPEG images

    Why it's wrong here

    JPEG images begin with the byte sequence 0xFFD8, not the 0x5A4D ("MZ") signature that uint16(0) tests at offset zero. The rule therefore never matches them. This option is tempting because YARA is commonly used to hunt images in malware campaigns, but a JPEG rule would check for the 0xFFD8 header instead.

  • ✗

    Linux ELF files

    Why it's wrong here

    ELF files begin with the magic bytes 0x7f454c46, not 0x5a4d, so the uint16(0) test fails immediately. The rule targets Windows PE executables; ELF would be selected only if the condition checked the ELF magic value at offset zero.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.