200-201 Host-Based Analysis Practice Question
An analyst is reviewing a memory dump and uses Volatility's cmdline plugin to view process command lines. One process shows command line arguments that include a long base64-encoded string. What should the analyst suspect?
⚠ Common exam trap
Cisco often tests the distinction between encoding and encryption, where candidates mistakenly think base64 is encryption or a hash, when it is actually a reversible encoding used for obfuscation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process may be running obfuscated malicious code
The presence of a long base64-encoded string in a process command line is a strong indicator of obfuscation, commonly used by malware to hide payloads or configuration data from static analysis. Base64 encoding is not encryption; it is a simple encoding scheme that can be easily decoded, but it obscures the string's content from casual inspection. Volatility's cmdline plugin reveals this artifact, and an analyst should suspect that the process is executing obfuscated malicious code, as attackers frequently use this technique to evade signature-based detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The process may be running obfuscated malicious code
Why this is correct
Long base64-encoded command line arguments indicate encoded payloads, a common obfuscation technique used by malware to hide scripts or commands from casual inspection. Legitimate processes rarely pass such blobs as arguments, so the analyst should suspect obfuscated malicious code.
- ✗
The process is benign and the string is a normal parameter
Why it's wrong here
Treating the string as a normal benign parameter ignores that base64 in command-line arguments is a common obfuscation technique for hiding payloads or exfiltration data. Legitimate parameters are usually readable flags and paths. Assuming benignity without decoding the string misses potential compromise evidence in the memory dump.
- ✗
The string is a hash for integrity verification
Why it's wrong here
A hash for integrity verification is typically a fixed-length hexadecimal digest, not a long base64 string embedded in command-line arguments. Base64 encoding is used to obfuscate or transport binary payloads, so its presence in a command line points to encoded data or a staged payload rather than checksum verification.
- ✗
The process is using encryption
Why it's wrong here
Base64 is an encoding scheme for representing binary data as ASCII text, not an encryption algorithm; it provides no confidentiality and is trivially reversible. Encryption would produce ciphertext, not printable base64. The analyst should decode the string to reveal the actual command or payload rather than assume encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.