Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

An analyst receives a YARA rule that includes the string 'MZ' at the beginning of a file. What does this indicator typically help identify?

⚠ Common exam trap

Cisco often tests the concept of file magic numbers to see if candidates confuse the 'MZ' signature of Windows executables with other common file headers, such as '%PDF' for PDFs or 'PK' for ZIP archives, leading them to select a plausible but incorrect option like malicious documents or PDFs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows executable files

The string 'MZ' (0x4D 0x5A) is the magic number for the MS-DOS header, which is present at the very beginning of all Windows Portable Executable (PE) files, including .exe, .dll, and .sys files. A YARA rule that checks for 'MZ' at offset 0 is specifically targeting the PE file format, which is the standard executable format for Windows. This indicator helps an analyst quickly identify that a file is likely a Windows executable, regardless of its extension.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows executable files

    Why this is correct

    The ASCII bytes 'MZ' (0x4D5A) form the DOS header signature at offset zero of every Windows PE file, so a YARA rule matching 'MZ' at the start of a file identifies Windows executables. This satisfies the scenario's need to flag executable files by their magic number.

  • ✗

    PDF files with embedded JavaScript

    Why it's wrong here

    The 'MZ' magic bytes mark Windows PE executables, not PDFs, which begin with '%PDF'. Embedded JavaScript appears inside PDF objects, so a YARA rule targeting it would match those structures. This option would be correct if the rule were written to detect script-laden PDFs rather than the DOS header signature.

  • ✗

    Linux ELF binaries

    Why it's wrong here

    Linux ELF binaries start with the magic bytes 0x7F followed by 'ELF', so a rule anchored on 'MZ' cannot match them. The option tempts because YARA is commonly used to classify executable formats. It would be correct if the rule specified the ELF header instead of the DOS MZ signature.

  • ✗

    Malicious documents containing macros

    Why it's wrong here

    Macro-bearing documents are OLE or OOXML containers, whose headers are D0 CF 11 E0 or 'PK', not 'MZ'. The option tempts because malicious macros are a frequent YARA target. It would be the right choice if the rule matched VBA project streams or the compound file header rather than the PE signature.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.