200-201 Host-Based Analysis Practice Question
An analyst is investigating a Windows 10 workstation suspected of being compromised. The analyst runs `wmic process get name,processid,parentprocessid,commandline` and observes a process named `powershell.exe` with the command line `powershell -nop -w hidden -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAA...`. What does the `-enc` parameter indicate about how the command was executed?
⚠ Common exam trap
The trap here is assuming that `-enc` means encryption requiring a decryption key, when it actually refers to Base64 encoding that anyone can decode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The command was Base64-encoded to obfuscate its contents.
The `-enc` parameter in PowerShell stands for `-EncodedCommand`, which accepts a Base64-encoded string representing the actual command. Attackers use it to obfuscate malicious scripts and bypass simple command-line logging. An analyst should decode the Base64 string to reveal the true intent, such as downloading a payload or establishing persistence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The command was encrypted with AES and requires a key to decrypt.
Why it's wrong here
PowerShell's `-enc` parameter does not perform encryption; it only decodes a Base64 string. No cryptographic key is involved. The term 'enc' is misleading, but it stands for 'encoded,' not 'encrypted.' An analyst can trivially decode the string without any secret key.
- ✗
The command was signed with a digital certificate to appear legitimate.
Why it's wrong here
The `-enc` parameter has nothing to do with code signing. Digital signatures are separate and would be verified via `Get-AuthenticodeSignature`. Attackers using `-enc` typically do not sign their scripts; instead, they rely on obfuscation to evade detection. Confusing encoding with signing would misdirect the investigation.
- ✓
The command was Base64-encoded to obfuscate its contents.
Why this is correct
The `-enc` parameter (short for `-EncodedCommand`) tells PowerShell to interpret the following string as Base64-encoded UTF-16LE text. Attackers use this to hide malicious scripts from command-line logging and casual inspection. Decoding the Base64 string reveals the actual PowerShell commands, which often download or execute further payloads.
- ✗
The command was compressed using gzip to reduce its size.
Why it's wrong here
PowerShell's `-enc` parameter does not perform compression. The string is simply Base64-encoded, which can increase size rather than reduce it. Compression is not part of the `-EncodedCommand` functionality. Assuming compression would lead an analyst to use the wrong decoding method.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.