Courseiva
Host-Based Analysis →mediumMultiple Select

200-201 Host-Based Analysis Practice Question

An analyst is investigating a Windows host that likely has malware persistence via the registry. Which TWO registry hives are commonly used to store Run keys for user logon persistence? (Select 2)

⚠ Common exam trap

Cisco often tests the distinction between Run keys (user logon persistence) and other registry locations like AppInit_DLLs or Services, so candidates must know that only the Run paths under HKLM and HKCU are correct for this specific persistence method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

The Run keys under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run are standard locations where Windows executes programs automatically at user logon. Malware commonly writes entries to these keys to achieve persistence, making them critical for host-based analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HKEY_CLASSES_ROOT\*\shell

    Why it's wrong here

    Shell keys under HKEY_CLASSES_ROOT define context-menu handler commands, executing on user interaction rather than at logon. It tempts because shell extension hijacking is real persistence, and this path is correct when investigating right-click menu-based execution instead of Run keys.

  • ✓

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Why this is correct

    The HKLM Run key executes listed programs at logon for every user on the host, making it a machine-wide persistence location. This satisfies the stem's user logon persistence constraint, since malware written here survives reboots and affects all accounts.

  • ✗

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppInit_DLLs

    Why it's wrong here

    AppInit_DLLs loads a DLL into every process loading User32.dll, which is process-injection persistence, not logon Run-key execution. It tempts because it is a legitimate, frequently abused autostart location, and it is the right answer when the question asks about AppInit persistence.

  • ✗

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

    Why it's wrong here

    Services keys host Windows service executables and drivers, giving persistence via service creation rather than logon Run keys. It tempts because services are a genuine, widely abused autostart mechanism, and this path is the correct answer when investigating service-based persistence instead.

  • ✓

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

    Why this is correct

    The HKCU Run key executes listed programs at logon for the specific user profile only, scoping persistence to that account. This satisfies the stem's user logon persistence constraint, and it often evades detection because per-user hives are inspected less frequently.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.