Courseiva
Host-Based Analysis →mediumMultiple Choice

200-201 Host-Based Analysis Practice Question

An analyst is investigating a Linux host and runs 'cat /proc/1234/cmdline'. What information does this provide?

⚠ Common exam trap

Watch out — candidates often confuse the various /proc/PID pseudo-files — candidates often pick environ or maps because they vaguely remember 'something about process info in /proc' without mapping the exact filename to the exact data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The command line and arguments used to start the process

The file /proc/1234/cmdline is a pseudo-file exposed by the Linux kernel's procfs for the process with PID 1234. Reading it returns the exact command line and arguments that were passed to execve() when the process was started, with arguments separated by NUL bytes. This is why 'cat' often shows the arguments run together — the NUL separators are not rendered as visible characters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The memory map of the process

    Why it's wrong here

    /proc/1234/cmdline holds the command-line arguments, whereas the memory map lives in /proc/1234/maps. Analysts often inspect maps for loaded libraries and memory regions during malware triage, making it a plausible pick, but cmdline reveals only the invocation string.

  • ✓

    The command line and arguments used to start the process

    Why this is correct

    Reading `/proc/<pid>/cmdline` returns the exact command line and arguments that launched process 1234, with arguments separated by null bytes. This directly satisfies the scenario's requirement to identify how the process was started on the Linux host, exposing suspicious flags or scripts an attacker used.

  • ✗

    The environment variables of the process

    Why it's wrong here

    Environment variables sit in /proc/1234/environ, not cmdline, which contains only the argument vector. Environ is tempting because credentials and paths frequently leak there during incident response, but reading cmdline yields the executed command and its arguments instead.

  • ✗

    The current working directory of the process

    Why it's wrong here

    /proc/1234/cmdline exposes the process's command-line arguments, not its working directory; that resides in /proc/1234/cwd. The cwd symlink is the tempting target when tracing a process's file activity, but cmdline answers what was executed, not where it runs.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.