200-201 Host-Based Analysis Practice Question
An analyst uses Volatility on a memory dump and runs the 'pstree' command. What specific information does this provide compared to 'pslist'?
⚠ Common exam trap
200-201 often tests the specific output of Volatility plugins, and candidates confuse 'pstree' (hierarchy) with 'pslist' (flat list) or 'psscan' (hidden process detection) — the key is remembering that 'pstree' adds parent-child visualization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It displays the process tree hierarchy.
The Volatility 'pstree' plugin displays the process tree hierarchy, showing parent-child relationships between processes. Unlike 'pslist', which lists processes in a flat table ordered by creation time, 'pstree' visually indents child processes under their parents. This helps analysts identify suspicious process lineage, such as a web server spawning a shell.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It shows only hidden processes.
Why it's wrong here
Pstree displays the full process tree, not a hidden-only subset; hidden processes appear through other plugins such as psxview, which cross-references multiple sources. Pstree's value is the parent-child hierarchy, revealing processes spawned by unexpected parents.
- ✗
It extracts command line arguments.
Why it's wrong here
Command-line arguments come from the cmdline plugin, not pstree. pstree's actual output is the parent-child process hierarchy, showing which process spawned which — pslist merely lists processes flatly. Extracting arguments would be the right answer if the question asked how to recover what a suspicious process was executed with.
- ✓
It displays the process tree hierarchy.
Why this is correct
The pstree plugin reconstructs parent-child relationships by following inherited process identifiers, revealing the ancestry and nesting that pslist's flat enumeration omits. This satisfies the stem's comparison requirement, exposing processes whose parent has exited and been reparented, which a simple listing cannot show.
- ✗
It lists loaded kernel modules.
Why it's wrong here
pstree renders parent-child process relationships, not loaded kernel modules, so it cannot enumerate drivers; that is modules' role. It is tempting because pstree does expose structural memory-resident artefacts beyond pslist's flat listing, and would be the right choice when the analyst needs to trace process ancestry or spot a suspicious parent spawning children.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.