200-201 Host-Based Analysis Practice Question
An analyst uses 'sc query' on a Windows host and finds a service named 'WindowsUpdate' with a binary path pointing to 'C:\Users\Public\update.exe'. The service is running. Why is this suspicious?
⚠ Common exam trap
Cisco often tests the misconception that a service name or display name alone is the red flag, when in fact the critical indicator is the binary path location outside of system directories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The binary path is not in a system directory
Legitimate Windows services, especially those mimicking system components like Windows Update, should have their binary paths in protected system directories (e.g., C:\Windows\System32). A binary path pointing to C:\Users\Public\update.exe indicates the executable is in a user-writable location, which is a common technique used by malware to evade detection and maintain persistence. The 'sc query' command reveals the service configuration, and this abnormal path is a strong indicator of compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The service is running
Why it's wrong here
Many legitimate services run continuously, so running state alone proves nothing. It is tempting because a suspicious service being active suggests immediate compromise, prompting containment. The actual anomaly is the binary path 'C:\Users\Public\update.exe', a user-writable location no genuine Windows Update service would use.
- ✗
The service name is misspelled
Why it's wrong here
The name 'WindowsUpdate' is correctly spelled, so this is not the anomaly. It is tempting because typos in service names do indicate masquerading malware, and checking spelling is a valid triage step. Here the real indicator is the binary path outside System32, in a user-writable directory.
- ✗
The service displays 'WindowsUpdate'
Why it's wrong here
Displaying the name 'WindowsUpdate' is expected behaviour for a service and is not itself suspicious. It is tempting because attackers frequently masquerade using trusted names, and name-checking is a reasonable triage habit. The genuine indicator is the binary path residing in C:\Users\Public rather than System32.
- ✓
The binary path is not in a system directory
Why this is correct
Legitimate Windows services almost always execute from protected system locations such as C:\Windows\System32, not user-writable directories. C:\Users\Public is world-writable, allowing any local user to replace update.exe and gain persistence with SYSTEM privileges, since the service runs under a privileged account. This path anomaly satisfies the stem's suspicion constraint.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.