200-201 Host-Based Analysis Practice Question
An analyst is reviewing a Linux host that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees that the symbolic link points to '/tmp/.hidden/backdoor'. The process with PID 1234 is owned by root and was started from an unknown parent process. Which of the following best describes what the analyst has discovered?
⚠ Common exam trap
The trap here is assuming that any process running from /tmp is automatically malicious, but in this context the combination of root ownership, hidden directory, and unknown parent strongly indicates compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process is a malicious binary running from a non-standard location, indicating a potential compromise.
The /proc/PID/exe symbolic link reveals the actual executable file backing a running process. A root-owned process executing from a hidden directory under /tmp is a classic sign of malware or an attacker's backdoor, as legitimate system processes rarely reside there. This discovery warrants immediate further investigation, such as examining the binary and its network connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The process is a kernel thread that has been incorrectly linked to a user-space file.
Why it's wrong here
Kernel threads do not have a user-space executable and typically show an empty or special target for /proc/PID/exe. The presence of a valid path to a file in /tmp indicates a user-space process, not a kernel thread. This option misinterprets the nature of kernel threads and the information provided by the /proc filesystem.
- ✗
The process is a legitimate system daemon that has been relocated to /tmp for performance reasons.
Why it's wrong here
Legitimate system daemons are typically located in standard directories such as /usr/sbin, /usr/bin, or /sbin, not in /tmp. The presence of a hidden directory like /tmp/.hidden/backdoor is a strong indicator of malicious activity, as attackers often use /tmp for its world-writable permissions and to evade detection. This option incorrectly assumes benign intent without evidence.
- ✗
The process is a containerized application that uses /tmp as its working directory.
Why it's wrong here
While containerized applications might use /tmp, the executable itself is usually located in the container's filesystem, not directly in /tmp on the host. The scenario does not mention containers, and the hidden directory and root ownership are more indicative of a compromise. This option introduces an unsupported assumption about containerization.
- ✓
The process is a malicious binary running from a non-standard location, indicating a potential compromise.
Why this is correct
The /proc/1234/exe link points to the executable file of the process. A root-owned process running from /tmp/.hidden/backdoor is highly suspicious because /tmp is commonly used by attackers to drop and execute malware, and the hidden directory name suggests an attempt to avoid casual observation. This is a clear indicator of compromise.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.