Courseiva
Host-Based Analysis →hardMultiple Choice

200-201 Host-Based Analysis Practice Question

An analyst is triaging a Windows 10 host and finds a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from C:\Users\Public\update.ps1 every 30 minutes. The script base64-decodes a payload and calls Invoke-WebRequest to a remote host. Which action should the analyst take FIRST to preserve evidence while containing the threat?

⚠ Common exam trap

The trap here is jumping straight to remediation actions such as rebooting, deleting the task, or running antivirus, which destroy volatile evidence before it can be captured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture volatile data including the running process list, network connections, and the contents of C:\Users\Public\update.ps1, then disable the scheduled task and isolate the host.

The order of volatility dictates that the most perishable evidence (memory, network state, running processes) is captured before less volatile evidence (disk files) and before any remediation. Capturing the script, process list, and connections first preserves investigative value; disabling the task and isolating the host then stops the beaconing without destroying evidence. Reboots, AV quarantine, and deletion all destroy or alter artifacts needed to scope the compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately reboot the host into Safe Mode to stop the PowerShell execution, then begin collecting forensic artifacts from the disk.

    Why it's wrong here

    Rebooting destroys volatile evidence such as running processes, network connections, and in-memory payloads. Safe Mode does not remove scheduled tasks or persistence, so the threat would return on next boot. The analyst would lose critical data needed to scope the intrusion. Rebooting before acquisition violates the order of volatility and undermines the investigation.

  • ✗

    Run a full antivirus scan and allow it to quarantine any detected files, then review the scheduled task XML for indicators.

    Why it's wrong here

    Antivirus quarantine alters or removes the malicious script before the analyst can examine it, destroying evidence and potentially tipping off the attacker. A full scan also takes time during which the host remains beaconing to the command-and-control server. Evidence preservation must precede remediation, and the analyst should capture the script and task XML manually before any automated cleanup.

  • ✗

    Delete the scheduled task and the update.ps1 file immediately, then capture a memory image of the host for offline analysis.

    Why it's wrong here

    Deleting the task and script removes the primary evidence the analyst needs to determine what the payload did and where it communicated. A memory image captured afterward may lack the script content and related command history. The correct sequence is to collect volatile and file-based evidence first, then remediate. Premature deletion undermines both containment justification and later threat intelligence.

  • ✓

    Capture volatile data including the running process list, network connections, and the contents of C:\Users\Public\update.ps1, then disable the scheduled task and isolate the host.

    Why this is correct

    Volatile artifacts such as memory-resident processes, active network connections, and the malicious script file can disappear on reboot or be deleted by the attacker. Capturing them first preserves evidence for later analysis. Only after acquisition should the analyst disable the task and isolate the host to stop reinfection. This order follows the standard order of volatility principle in incident response.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.