Courseiva

200-201 · domain

Host-Based Analysis

Host-Based Analysis covers endpoint evidence collection and interpretation on Windows and Linux systems. You must identify malicious processes, persistence mechanisms, and user activity artifacts, then map findings to the correct forensic tool or file location. Questions present investigation scenarios and ask which commands, registry hives, or files reveal the needed evidence.

118 questions26 easy57 medium35 hard

Focused practice

Practice Host-Based Analysis questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Host-Based Analysis

Be able to select the right forensic artifact for a scenario: Volatility plugins for Windows memory, correct registry hives for persistence, and Linux cron and history file paths. The most important thing is matching the investigative question to the exact command or file that answers it.

Volatility plugins such as pslist, pstree, and dlllist for examining Windows process memory artifacts

Windows registry Run keys under HKCU and HKLM for user logon persistence detection

Linux user cron job locations including /var/spool/cron and crontab entries

Linux shell history files such as .bash_history for reconstructing executed commands

Watch out for

Common Host-Based Analysis exam traps

  • ▸Confusing Volatility plugins that list processes with those that dump memory or network connections, selecting irrelevant commands for process analysis.
  • ▸Assuming all Run key persistence lives in HKLM, missing per-user HKCU hives that malware commonly abuses.
  • ▸Checking only system-wide cron directories and overlooking user-specific crontab storage locations where unauthorized jobs hide.

Question index

All Host-Based Analysis questions (118)

Click any question to see the full explanation, or start a practice session above.

1

A security analyst is examining a Windows 10 host and suspects that an attacker has established persistence using a scheduled task. The analyst runs 'schtasks /query /fo LIST /v' and observes a task named 'WindowsUpdateCheck' with the action 'C:\Users\Public\update.exe' and a trigger set to run every 5 minutes. Which of the following best describes the attacker's technique?

Hard
2

A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the ASCII string 'MZ' at the beginning. What does this indicate?

Medium
3

An analyst is examining a Linux system for signs of an attacker establishing persistence. Which TWO of the following locations should the analyst check? (Choose two.)

Medium
4

An analyst is examining a Windows 10 host and discovers that a service named 'WinDefendSvc' is registered with a binary path of C:\ProgramData\svchost.exe and a display name of 'Windows Defender Service'. The legitimate Windows Defender service uses a different name and binary path. Which conclusion is most accurate?

Hard
5

When analyzing a suspicious PE file, the analyst calculates the file's entropy and finds it to be 7.8. What does a high entropy value typically indicate, and why is it relevant to malware analysis?

Hard
6

A security analyst is investigating a Windows host for signs of fileless malware. The analyst runs a memory analysis tool and observes a process named 'powershell.exe' with a parent process of 'winword.exe'. The command line includes '-enc' followed by a long base64 string. Which technique is most likely being used by the attacker?

Hard
7

Which Windows artifact stores evidence of file execution, including the path and run count, and is located in C:\Windows\Prefetch?

Easy
8

A Linux administrator checks authentication logs to investigate a possible brute-force attack. Which log file typically contains records of successful and failed SSH login attempts?

Easy
9

An analyst uses Volatility on a memory dump and runs the 'pstree' command. What specific information does this provide compared to 'pslist'?

Medium
10

When performing file analysis, which method is most reliable for determining the actual file type regardless of its extension?

Easy
11

A security analyst is investigating a Linux server that was compromised. The attacker used a rootkit to hide processes and files. The analyst runs 'lsmod' and notices a kernel module named 'hideproc' that is not recognized. Which command should the analyst use to determine the module's file path and potentially identify the rootkit?

Hard
12

During memory analysis using Volatility, an analyst wants to identify processes with suspicious network connections and potentially injected code. Which THREE plugins should the analyst use? (Select THREE)

Medium
13

An analyst is examining a suspicious file that appears to be a PDF but when checking the magic bytes at offset 0, sees '50 4B 03 04'. What does this indicate?

Medium
14

A security analyst is examining a Linux server that is suspected of being compromised. The analyst runs `ls -l /proc/<PID>/exe` for a suspicious process and sees that the symbolic link points to `/tmp/.hidden/update` but the file no longer exists on disk. Which conclusion is most accurate?

Hard
15

A security analyst is investigating a Windows host suspected of malware infection. Which tool would allow the analyst to view parent-child relationships of running processes and inspect command line arguments?

Easy
16

An analyst is examining a Linux server and notices an unusual systemd service that starts automatically. Which command would be used to disable this service?

Medium
17

A security analyst is reviewing a Windows system for signs of malware persistence. The analyst notices a suspicious executable named 'updater.exe' in the Startup folder. Which Windows feature is being abused by the malware in this scenario?

Easy
18

A Linux host has an unusual cron job that runs a script from /tmp every minute. The analyst checks /etc/crontab and /var/spool/cron/ but finds nothing. Where else could the cron job be defined?

Hard
19

A security analyst is examining a Linux system for signs of a rootkit. The analyst runs `lsmod` and notices a kernel module named `hideproc` that is not recognized. The analyst then runs `rmmod hideproc` but receives an error that the module is in use. Which of the following is the MOST likely reason the module cannot be removed?

Hard
20

An analyst is investigating a Windows system for potential malware persistence. The analyst discovers a scheduled task that runs a PowerShell script every hour. The script downloads and executes a payload from a remote server. Which of the following Windows artifacts would BEST provide the original creation time and the author of this scheduled task?

Medium
21

An analyst finds a registry modification under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options'. What is the primary use of this registry key?

Medium
22

An analyst is using Volatility to analyze a memory dump. Which TWO plugins are most effective for detecting code injection?

Hard
23

A security analyst is reviewing Windows Event Logs on a domain controller. The analyst sees multiple Event ID 4769 (Kerberos service ticket was requested) with the same user account but different service names, occurring in a short time frame. Which of the following attacks is MOST likely indicated?

Medium
24

An analyst is investigating a Windows system for signs of malware persistence. Which TWO registry locations are commonly used by malware to achieve automatic startup? (Choose two.)

Medium
25

An analyst is examining a Windows system for evidence of credential dumping. The analyst runs 'Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4688}' and filters for processes with 'lsass.exe' as the target. The output shows that a process named 'procdump.exe' was executed with the command line 'procdump.exe -ma lsass.exe lsass.dmp'. Which type of attack does this indicate?

Hard
26

A Windows event log review shows Event ID 4625 multiple times from a single source IP. What does this event indicate, and which log contains it?

Medium
27

A Windows Event Log shows Event ID 4625 multiple times from the same source IP address. What type of activity does this indicate?

Medium
28

A threat hunter is examining a Windows 10 host and wants to determine whether a suspicious executable was recently run by a user. The hunter knows that Windows records application execution history in the registry under the UserAssist key. Which location should the hunter inspect to find this data for the currently logged-on user?

Hard
29

During incident response on a Linux server, an analyst runs 'ss -tlnp' and sees an SSH service listening on a non-standard high port. Which step should the analyst take next to investigate potential unauthorized access?

Medium
30

A security analyst is investigating a Linux server that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees the output: '/proc/1234/exe -> /tmp/.hidden/backdoor (deleted)'. What does this output indicate?

Hard
31

During forensic analysis of a Windows host, an analyst finds a file in C:\Windows\Prefetch with the name 'MALWARE.EXE-3F2A1B0C.pf'. Which type of information can be extracted from this prefetch file to assist the investigation?

Hard
32

A security analyst is triaging a Windows server that may have been compromised. The analyst needs to identify which network connections are currently established by processes on the host and which executable is responsible for each connection. Which two native tools provide this information? (Choose two.)

Medium
33

An analyst is investigating a Windows system for signs of malware persistence. Which registry key is commonly used by malware to run automatically at user logon?

Easy
34

An analyst is analyzing a suspicious PE file. The file's entropy is high (close to 8.0), and the section names appear random. What does this likely indicate?

Hard
35

A security analyst is examining a Linux system for signs of a compromised user account. The analyst runs `grep ':0:0:' /etc/passwd` and finds an entry for user `backup` with UID 0. The legitimate backup user should have a UID of 1001. Which of the following is the MOST likely explanation?

Medium
36

A Windows analyst uses Process Explorer to investigate parent-child relationships. Which TWO characteristics are commonly associated with malicious processes?

Easy
37

A CyberOps analyst is examining a Windows workstation and finds that a scheduled task named 'MicrosoftEdgeUpdateTask' exists in Task Scheduler, but the Task Scheduler GUI shows it as disabled. The analyst suspects it was created by malware to masquerade as a legitimate updater. Which artifact should the analyst check to determine the exact executable path and arguments the task would run if it were enabled?

Hard
38

An analyst is reviewing Windows Security Event Logs and finds Event ID 4648. What does this event indicate?

Medium
39

A security analyst is analyzing a Linux system suspected of being used as a phishing server. Which THREE artifacts should the analyst examine to identify persistence mechanisms? (Select 3)

Hard
40

An analyst is reviewing a memory dump and uses Volatility's cmdline plugin to view process command lines. One process shows command line arguments that include a long base64-encoded string. What should the analyst suspect?

Hard
41

During a host investigation on a Windows 10 endpoint, an analyst wants to review the history of commands typed into PowerShell consoles by interactive users. Which artifact should the analyst examine?

Easy
42

In Linux forensics, which file would an analyst check to see command history of a user, potentially revealing malicious commands executed?

Easy
43

A security analyst is examining a Linux web server that is suspected of being compromised. The analyst runs `ps aux` and notices a process named `apache2` running as the user `www-data`, but its parent process ID (PPID) is 1 (init/systemd). Normally, `apache2` is started by a master process. What is the most likely explanation for this anomaly?

Easy
44

A security analyst is examining a Windows 10 endpoint that is suspected of being infected with malware. The analyst runs 'Get-WinEvent -LogName Security | Where-Object {$_.Id -eq 4688}' and notices that a process named 'cmd.exe' was launched with the command line 'cmd /c vssadmin.exe delete shadows /all /quiet'. Which type of attack does this command indicate?

Easy
45

During memory analysis using Volatility, an analyst wants to identify processes that may be hiding. Which TWO plugins are most useful for detecting hidden or injected code? (Choose two.)

Medium
46

An analyst is investigating a Linux system and wants to view the current network connections. Which command is most appropriate to list listening TCP ports along with the associated processes?

Medium
47

A security analyst is investigating a Linux host for signs of compromise. The analyst runs `ps aux` and notices a process named `kworker` with a high CPU usage. The analyst suspects this may be a masquerading malware process. Which TWO commands should the analyst use to verify whether this process is legitimate or malicious? (Choose two.)

Medium
48

Which Windows Prefetch file extension indicates that a program has been executed on the system?

Easy
49

An analyst is analyzing a Linux system that may have been compromised. Which THREE artifacts would provide evidence of attacker activity? (Choose three.)

Hard
50

An analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about this process? (Choose three.)

Hard
51

A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the MZ header (4D 5A). The file's entropy is calculated as 7.8. What does the high entropy most likely indicate?

Hard
52

A security analyst is examining a Linux host and wants to identify which user account was used to execute a specific command that modified a critical system file. Which of the following files would provide the MOST direct evidence of the user who executed the command?

Easy
53

A security analyst is reviewing a Windows host for indicators of credential dumping. The analyst wants to identify artifacts that commonly indicate tools such as Mimikatz have been used on the system. Which two artifacts should the analyst look for? (Choose two.)

Medium
54

A Linux server has been compromised. The analyst checks for persistence mechanisms. Which THREE of the following are common Linux persistence techniques that should be examined? (Select THREE)

Hard
55

An analyst uses 'sc query' on a Windows host and finds a service named 'WindowsUpdate' with a binary path pointing to 'C:\Users\Public\update.exe'. The service is running. Why is this suspicious?

Medium
56

An analyst is reviewing Windows Event Logs and sees multiple Event ID 4625 entries from a single IP address. What does this indicate?

Medium
57

A security analyst is investigating a Windows host and wants to view running processes along with their parent-child relationships and command-line arguments. Which tool is best suited for this task?

Easy
58

During an incident response engagement, an analyst is examining a Windows Server 2019 host that is suspected of being compromised. The analyst wants to determine which user accounts were used to log on interactively to the console in the last 24 hours. Which Windows artifact should the analyst query to obtain this information?

Hard
59

An analyst is investigating a Windows 10 workstation suspected of being compromised. The analyst runs `wmic process get name,processid,parentprocessid,commandline` and observes a process named `powershell.exe` with the command line `powershell -nop -w hidden -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAA...`. What does the `-enc` parameter indicate about how the command was executed?

Medium
60

An analyst runs Volatility's pstree plugin on a memory dump. The output shows that a process 'svchost.exe' is the child of 'explorer.exe'. What is suspicious about this?

Medium
61

A forensic analyst uses Volatility on a memory dump and runs the 'malfind' plugin. The output shows a process with a VAD region that has PAGE_EXECUTE_READWRITE protection and contains the pattern 'MZ'. What does this indicate?

Hard
62

A SOC analyst is reviewing a Windows 10 endpoint after a suspected compromise. They need to determine which user account was responsible for a specific process that was launched shortly before the alert. Which Windows artifact directly records the user account associated with process creation events and should be queried using Windows Event Log?

Medium
63

A SOC analyst receives an alert about a Windows workstation that may be infected with malware. The analyst wants to examine the system's boot configuration to determine if the malware modified boot settings to disable driver signature enforcement. Which Windows tool should the analyst use to view the current boot configuration data?

Medium
64

A security analyst is analyzing a memory dump from a compromised Windows system using Volatility. Which command would best reveal hidden or injected code within a process?

Hard
65

Which Windows Event ID corresponds to a successful user logon?

Easy
66

A security analyst is reviewing a Windows 10 endpoint that is suspected of being compromised. The analyst opens Task Manager and notices a process named 'lsass.exe' running with a PID of 1234, but its parent process is 'cmd.exe' rather than 'wininit.exe'. The analyst also observes that the process path is 'C:\Users\Public\lsass.exe'. Which type of attack is most likely indicated by these findings?

Medium
67

An analyst uses Volatility's 'netscan' on a memory dump and finds an established connection to an external IP on port 4444. Which type of activity is this commonly associated with?

Medium
68

A security analyst is investigating a Linux server that is suspected of hosting a reverse-shell backdoor. The analyst wants to identify which running process is maintaining the outbound connection and which user context it is running under. Which TWO commands would best provide this information? (Choose two.)

Medium
69

An analyst is reviewing a Linux host that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees that the symbolic link points to '/tmp/.hidden/backdoor'. The process with PID 1234 is owned by root and was started from an unknown parent process. Which of the following best describes what the analyst has discovered?

Medium
70

A security analyst suspects that a Windows workstation was compromised by malware that schedules a recurring task to maintain persistence. The analyst opens Task Scheduler and sees dozens of scheduled tasks. Which built-in command-line utility should the analyst use to export a detailed list of all scheduled tasks, including the actions they perform, so the list can be reviewed offline?

Medium
71

In a Linux system, an analyst wants to check for unauthorized cron jobs. Which of the following is a common location for user-specific cron jobs?

Medium
72

An analyst finds an unknown scheduled task on a Windows system that runs a PowerShell script at system startup. Which tool is best for examining the task's trigger and actions?

Medium
73

An analyst is triaging a Windows 10 host and finds a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from C:\Users\Public\update.ps1 every 30 minutes. The script base64-decodes a payload and calls Invoke-WebRequest to a remote host. Which action should the analyst take FIRST to preserve evidence while containing the threat?

Hard
74

A Windows system's security log shows Event ID 4720 followed by 4726 for the same username within minutes. What does this sequence indicate?

Medium
75

Which Windows Event ID is recorded when a user account is created, indicating potential unauthorized account creation?

Easy
76

An analyst is investigating a Linux system for persistence mechanisms. Which TWO of the following are common locations for cron-based persistence? (Select TWO)

Easy
77

A Windows Event Log analysis reveals Event ID 4720 and 4726 occurrences for the same account within a short time. Which TWO actions were performed? (Select 2)

Medium
78

A security analyst is reviewing a Windows workstation that is suspected of being infected with malware that establishes persistence. The analyst wants to check a location that is commonly used by malware to automatically start when a user logs on. Which of the following should the analyst examine?

Easy
79

An analyst wants to determine if a specific executable has been run on a Windows system. Which artifact provides evidence of prior execution?

Easy
80

A security analyst is reviewing a Windows 10 host for potential compromise. The analyst runs 'net user' and sees an account named 'Support' that was not created by IT. The account is a member of the local Administrators group. Which Windows Event ID should the analyst check to determine when this account was created?

Medium
81

An analyst needs to check for services that were set to start automatically on a Windows host. Which command-line utility can be used to query the state and start type of all services?

Easy
82

An analyst examining a Linux server notices an unusual cron job in /etc/crontab that runs a script every 5 minutes. Which of the following describes the best approach to determine if this cron job is malicious?

Hard
83

An analyst is performing memory forensics on a Windows machine using Volatility. Which command would be most useful to identify hidden or injected code within a process?

Medium
84

A forensic analyst is examining a suspicious file. The file has a high entropy score (close to 8.0) and the PE section names are obfuscated. Which tool or technique would best help determine if the file is packed?

Hard
85

A security analyst is investigating a Windows workstation that experienced a series of failed logon attempts followed by a successful logon. Which TWO Windows Event IDs should the analyst examine to understand this activity?

Medium
86

An analyst is analyzing a suspicious executable file. Using the 'file' command, it returns 'data' instead of 'PE32 executable'. What is the most likely reason?

Medium
87

An analyst discovers a suspicious service on a Windows host. Which command can be used to query the status and details of services from the command line?

Easy
88

An analyst is investigating a Linux server and suspects that an attacker has established persistence by modifying system startup scripts. The analyst runs 'ls -la /etc/rc.local' and finds it has been modified recently. Which TWO additional artifacts should the analyst examine to identify other potential persistence mechanisms? (Choose two.)

Hard
89

An analyst is reviewing logs on a Windows 10 host that is suspected of being compromised. The analyst runs 'wevtutil qe Security /q:"*[System[(EventID=4688)]]" /f:text' and sees that a process named 'powershell.exe' was launched by 'winword.exe' with the command line 'powershell -nop -w hidden -enc SQBFAFgA...'. Which type of malicious activity does this most likely indicate?

Medium
90

A security analyst is examining a Windows 10 endpoint suspected of compromise. The analyst runs `wmic process get name,processid,executablepath,parentprocessid` and observes a process named `lsass.exe` with PID 1234 and executable path `C:\Windows\Temp\lsass.exe`. The legitimate lsass.exe should reside in `C:\Windows\System32`. Which of the following is the MOST likely explanation?

Hard
91

During a host-based analysis, a Windows system is found to have a suspicious service that starts automatically. Which command-line tool can be used to query the status and configuration of services, particularly to identify non-standard service names or paths?

Medium
92

A SOC analyst is reviewing a Windows 10 endpoint that is suspected of being compromised by malware that hides its network connections. The analyst runs 'netstat -anob' on the live system but does not see any suspicious outbound connections. Which Windows artifact should the analyst examine next to identify network connections that may have been hidden from the live API?

Medium
93

A security analyst is reviewing Windows Event Logs to determine if a user account was recently created on a compromised host. Which Windows Event ID should the analyst look for in the Security log to identify user account creation events?

Easy
94

An analyst is examining a Windows system for evidence of malware that maintains persistence by modifying the Image File Execution Options (IFEO) registry key. Which of the following best describes how this technique works?

Medium
95

An analyst is reviewing Windows Event Logs and finds Event ID 4648. What does this event typically indicate?

Medium
96

A threat hunter is examining a Linux web server that is suspected of being compromised. The hunter wants to identify suspicious processes that may be communicating with external command-and-control infrastructure and to understand what files those processes have open. Which TWO artifacts or commands should the hunter use to accomplish these goals? (Choose two.)

Medium
97

An analyst is investigating a Linux web server that is exhibiting unusual outbound network traffic. The analyst runs 'lsof -i' and notices that the process 'apache2' has an established connection to an external IP address on port 4444. Further investigation shows that a file named 'update.php' in the web root contains obfuscated code. Which type of compromise does this most likely represent?

Medium
98

A security analyst is investigating a Linux server that is exhibiting unusual outbound network traffic. The analyst runs 'netstat -tulpn' and observes a listening service on TCP port 4444, but the process name is 'sshd'. The analyst knows that SSH normally listens on port 22. Which of the following is the most likely explanation for this finding?

Hard
99

An analyst is reviewing Windows Event Logs and sees Event ID 4625. What does this event indicate?

Easy
100

An analyst is investigating a Windows system where a suspicious executable is running. Using Process Explorer, the analyst observes that the process 'svchost.exe' has a parent process of 'cmd.exe'. What is the significance of this parent-child relationship?

Medium
101

A security analyst is examining a Windows 10 host that is suspected of being compromised. The analyst runs `wmic process get name,processid,executablepath,commandline` and notices a process named `svchost.exe` with an executable path of `C:\Users\Public\svchost.exe`. Which conclusion is most accurate?

Hard
102

An incident responder is analyzing a Windows machine for evidence of malware persistence. Which TWO registry keys are commonly abused to achieve automatic execution at user logon?

Medium
103

An analyst is examining a Linux system for persistence mechanisms. Which of the following files should be reviewed to detect cron-based persistence?

Medium
104

During an incident response, an analyst checks for persistence mechanisms and finds an entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the most likely purpose of this registry key?

Medium
105

An analyst suspects a Windows workstation is beaconing to a command-and-control server. The host's DNS cache contains an entry for a domain that resolves to an IP address, but the analyst cannot find any active network connection or process associated with that domain. Which Windows artifact should the analyst examine to determine whether a process previously resolved this domain and when?

Medium
106

Which Linux log file is most appropriate for reviewing failed SSH login attempts?

Medium
107

An analyst is examining a PE file and notices that the 'TimeDateStamp' in the optional header is 0x00000000. What does this suggest?

Medium
108

A junior analyst is asked to review a Linux server for evidence of unauthorized access. They want to see a chronological record of authentication-related messages, including successful and failed logins, generated by the system's authentication services. Which file should the analyst examine?

Easy
109

A Linux analyst wants to identify all listening TCP ports on a system. Which command is most appropriate?

Easy
110

A junior analyst is triaging a Windows workstation that users report is running slowly. The analyst suspects a malicious process is persisting by masquerading as a legitimate Windows service. Which built-in Windows tool should the analyst use to view services, their binary paths, and their current state without installing additional software?

Easy
111

An analyst is investigating a Linux host and runs 'cat /proc/1234/cmdline'. What information does this provide?

Medium
112

An analyst is examining a suspicious PE file. The file's entropy is very high (close to 8.0) and the import table is almost empty. What does this indicate?

Hard
113

An analyst uses Volatility's pstree plugin on a memory dump. The output shows that process 'winlogon.exe' has a child process 'cmd.exe' that is not typical. What is the most likely explanation?

Hard
114

During a forensic examination of a Linux system, an analyst wants to check for persistence mechanisms. Which file or directory should be examined to find user-specific cron jobs that may have been added by an attacker?

Hard
115

An analyst is investigating a Windows host that likely has malware persistence via the registry. Which TWO registry hives are commonly used to store Run keys for user logon persistence? (Select 2)

Medium
116

In Windows, prefetch files (C:\Windows\Prefetch\*.pf) are used by the system to speed up application loading. How can an analyst leverage prefetch files during host-based analysis?

Medium
117

An analyst is investigating a Windows host for malware persistence. Which TWO registry locations are commonly abused for persistence by modifying the 'Run' key? (Select TWO)

Medium
118

An analyst is investigating a Windows workstation that exhibits suspicious outbound network traffic. The analyst suspects a malicious process is injecting code into a legitimate process. Which of the following Windows Event Log sources would MOST likely contain evidence of process creation and image loading that could reveal the injection?

Hard

Frequently asked questions

What does the Host-Based Analysis domain cover on the 200-201 exam?
Be able to select the right forensic artifact for a scenario: Volatility plugins for Windows memory, correct registry hives for persistence, and Linux cron and history file paths. The most important thing is matching the investigative question to the exact command or file that answers it.
How many questions are in this domain?
This page lists all 118 Host-Based Analysis questions in the 200-201 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Host-Based Analysis questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-cyberops-associate CISCO-CYBEROPS-ASSOCIATE cbrops host analysis Practice Questions