Courseiva

CCNA Host-Based Analysis Questions

43 of 118 questions · Page 2/2 · Host-Based Analysis · Answers revealed

76
Multi-Selecteasy

An analyst is investigating a Linux system for persistence mechanisms. Which TWO of the following are common locations for cron-based persistence? (Select TWO)

Select 2 answers
A./var/spool/cron/crontabs/
B./etc/init.d/
C./etc/crontab
D./var/log/cron
E./etc/systemd/system/
AnswersA, C

User crontab files are stored under /var/spool/cron/crontabs/, with one file per user, making it a standard location attackers modify to schedule recurring commands. This satisfies the cron persistence requirement, unlike directories holding system binaries or logs.

Why this answer

Option A (/var/spool/cron/crontabs/) is correct because this is the directory where per-user crontab files are stored on Debian/Ubuntu-style systems, and attackers commonly drop a crontab entry here to run a payload under a specific user account at scheduled intervals. Option C (/etc/crontab) is correct because it is the system-wide crontab file that supports the extra user field and is a frequent target for persistence, since a malicious line added here executes with the specified user's privileges on a recurring schedule. Option B (/etc/init.d/) is not cron-based; it holds SysV init scripts for service startup, not scheduled jobs.

Option D (/var/log/cron) is a log file recording cron activity, useful for detection but not a persistence location. Option E (/etc/systemd/system/) is for systemd unit files, a separate persistence mechanism from cron.

Exam trap

200-201 often tests distinguishing persistence mechanisms by category — candidates confuse cron locations with init/systemd service directories, picking /etc/init.d/ or /etc/systemd/system/ when the question specifically asks about cron.

77
Multi-Selectmedium

A Windows Event Log analysis reveals Event ID 4720 and 4726 occurrences for the same account within a short time. Which TWO actions were performed? (Select 2)

Select 2 answers
A.User account was locked
B.User account was deleted
C.Group policy was updated
D.User logged on successfully
E.User account was created
AnswersB, E

Event ID 4726 is logged by Windows Security auditing when a user account object is deleted from Active Directory. Its appearance for the same account shortly after creation confirms deletion occurred, matching the stem's request to identify the actions performed.

Why this answer

Event ID 4720 indicates account creation, and 4726 indicates account deletion. The rapid creation and deletion may indicate an attempt to avoid detection or create a temporary account.

78
MCQeasy

A security analyst is reviewing a Windows workstation that is suspected of being infected with malware that establishes persistence. The analyst wants to check a location that is commonly used by malware to automatically start when a user logs on. Which of the following should the analyst examine?

A.The Recycle Bin
B.The Prefetch folder
C.The Windows Defender quarantine folder
D.The Startup folder for the current user
AnswerD

The Startup folder (e.g., %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) contains shortcuts and executables that run automatically when the user logs on. Malware often places a copy or shortcut here to maintain persistence. Checking this folder is a standard step in host-based analysis for user-level persistence.

Why this answer

The Startup folder is a well-known user-level persistence location. Any program or shortcut placed there will execute automatically when the user logs on. Malware frequently uses this folder because it requires no administrative privileges and is easy to implement.

Analysts should check both the per-user Startup folder and the all-users Startup folder for suspicious entries.

Exam trap

The trap here is confusing forensic artifacts that record execution, such as Prefetch, with actual auto-start extensibility points like the Startup folder that cause execution.

79
MCQeasy

An analyst wants to determine if a specific executable has been run on a Windows system. Which artifact provides evidence of prior execution?

A.Registry Run keys
B.Task Scheduler logs
C.Prefetch files
D.Windows Event Logs
AnswerC

Prefetch files record execution metadata for each program, storing the executable name, run count and last-run timestamps in C:\Windows\Prefetch. This directly satisfies the requirement to evidence prior execution on the Windows system, unlike artefacts that merely show presence or download.

Why this answer

Prefetch files (.pf) are created by Windows when an executable runs, storing execution details such as the first eight file paths referenced and the last run time. Analyzing Prefetch files allows an analyst to determine if a specific executable has been executed, even if the executable itself has been deleted. This makes Prefetch the most direct artifact for evidence of prior execution.

Exam trap

Cisco often tests the misconception that Windows Event Logs (specifically Security Event ID 4688) are always enabled and capture all process executions, when in reality they require explicit audit policy configuration and are often not logging by default, making Prefetch a more reliable artifact for execution evidence.

How to eliminate wrong answers

Option A is wrong because Registry Run keys (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run) only indicate programs configured to start automatically at boot or user logon, not whether an arbitrary executable has been run. Option B is wrong because Task Scheduler logs record scheduled tasks and their execution history, but they do not capture execution of executables that were not scheduled. Option D is wrong because Windows Event Logs (e.g., Security log with Event ID 4688) can log process creation if auditing is enabled, but by default many systems do not log all process executions, making them unreliable for this specific forensic question.

80
MCQmedium

A security analyst is reviewing a Windows 10 host for potential compromise. The analyst runs 'net user' and sees an account named 'Support' that was not created by IT. The account is a member of the local Administrators group. Which Windows Event ID should the analyst check to determine when this account was created?

A.4722
B.4724
C.4720
D.4732
AnswerC

Event ID 4720 is logged when a user account is created. It includes the account name, the creator's username, and a timestamp. In this scenario, the analyst needs to determine when the suspicious 'Support' account was created, so 4720 is the correct event to look for. Reviewing this event can help identify the timeframe of the compromise and the account that created it, aiding further investigation.

Why this answer

The analyst needs to determine when the unauthorized 'Support' account was created. Event ID 4720 is specifically logged when a user account is created, providing the account name, creator, and timestamp. Other events like 4722 (enabled), 4724 (password reset), and 4732 (added to group) do not indicate creation time.

Therefore, 4720 is the correct event to review for account creation.

Exam trap

The trap here is confusing account creation with account enabling or group addition, which are logged under different Event IDs and do not provide the creation timestamp.

81
MCQeasy

An analyst needs to check for services that were set to start automatically on a Windows host. Which command-line utility can be used to query the state and start type of all services?

A.sc query
B.tasklist
C.schtasks
D.netstat
AnswerA

Correct. sc query lists service status and configuration.

Why this answer

The 'sc query' command retrieves information about services, including their state and start type (auto, manual, disabled). It is useful for identifying suspicious services.

82
MCQhard

An analyst examining a Linux server notices an unusual cron job in /etc/crontab that runs a script every 5 minutes. Which of the following describes the best approach to determine if this cron job is malicious?

A.Ignore it because cron jobs are always legitimate.
B.Delete the cron job immediately to stop potential malicious activity.
C.Check the script's content, owner, and compare its hash with known threats.
D.Run the script in a sandbox to see what it does.
AnswerC

Inspecting the script's content, owner and hash directly addresses the persistence mechanism: cron executes the referenced file, so its code, permissions and provenance reveal intent. Comparing the hash against threat intelligence confirms known malware, satisfying the need to determine whether this scheduled job is malicious rather than merely unusual.

Why this answer

Inspecting the script content and correlating with known persistence techniques helps assess maliciousness.

83
MCQmedium

An analyst is performing memory forensics on a Windows machine using Volatility. Which command would be most useful to identify hidden or injected code within a process?

A.dlllist
B.netscan
C.pslist
D.malfind
AnswerD

The malfind plugin scans process memory for pages exhibiting characteristics of injected or hidden code, such as executable regions lacking a corresponding mapped file on disk. That directly addresses the requirement to identify injected code within a process during Windows memory forensics.

Why this answer

The `malfind` plugin in Volatility is specifically designed to detect hidden or injected code in process memory. It scans for memory regions that are both executable and writable (or have no file backing on disk), which are common indicators of code injection techniques like process hollowing or reflective DLL injection. By identifying these suspicious memory pages, `malfind` helps analysts uncover malware that attempts to hide within legitimate processes.

Exam trap

The trap here is confusing memory analysis plugins: candidates might think `dlllist` or `pslist` can reveal hidden code, but only `malfind` specifically targets injected code by analyzing memory permissions and file backing.

How to eliminate wrong answers

Option A is wrong because `dlllist` enumerates loaded DLLs for each process, which can reveal unexpected modules but does not directly detect injected code that may not appear as a standard DLL. Option B is wrong because `netscan` scans for network artifacts (open sockets, connections) and is unrelated to finding hidden code in memory. Option C is wrong because `pslist` simply lists active processes, which may show a malicious process but does not analyze memory for injected code within a process.

84
MCQhard

A forensic analyst is examining a suspicious file. The file has a high entropy score (close to 8.0) and the PE section names are obfuscated. Which tool or technique would best help determine if the file is packed?

A.Use the 'strings' command to extract readable strings
B.Check the file's digital signature
C.Run the 'file' command in Linux
D.Analyze the PE sections and calculate entropy to detect packing
AnswerD

Analysing PE section entropy directly identifies packing: packed executables compress or encrypt their payload, producing entropy near 8.0 and obfuscated section names such as UPX0. This technique satisfies the stem's requirement to confirm packing by examining the suspicious file's structural characteristics rather than relying on runtime behaviour.

Why this answer

High entropy (close to 8.0) indicates the file's byte distribution is nearly random, which is characteristic of compressed or encrypted data — exactly what packers produce. Combined with obfuscated PE section names (e.g., UPX0, .aspack, or random strings), analyzing PE section headers and computing per-section entropy is the definitive method to confirm packing. Tools like PEiD, Detect It Easy, or pefile in Python automate this by flagging sections with entropy >7.0 and non-standard names.

Exam trap

The trap here is confusing file identification (the 'file' command) or string extraction with actual packer detection — candidates pick 'strings' because it's a common first-step tool, but entropy analysis of PE sections is the specific technique that answers the question.

How to eliminate wrong answers

Option A is wrong because 'strings' only extracts printable ASCII/Unicode sequences and cannot detect compression or encryption — packed files typically yield very few meaningful strings, but that alone is not diagnostic. Option B is wrong because digital signature verification only confirms authenticity and integrity; most malware is unsigned, and a valid signature says nothing about whether the binary is packed. Option C is wrong because the 'file' command only identifies the file type via magic bytes (e.g., 'PE32 executable') and does not analyze section entropy or detect packers.

85
Multi-Selectmedium

A security analyst is investigating a Windows workstation that experienced a series of failed logon attempts followed by a successful logon. Which TWO Windows Event IDs should the analyst examine to understand this activity?

Select 2 answers
A.4624 - An account was successfully logged on
B.4720 - A user account was created
C.4648 - A logon was attempted using explicit credentials
D.4776 - The domain controller attempted to validate the credentials for an account
E.4625 - An account failed to log on
AnswersA, E

Event ID 4624 records the successful logon that terminated the brute-force sequence, satisfying the stem's requirement to examine the outcome following repeated failures. Its logon type field distinguishes interactive, network, and remote access, letting the analyst confirm whether the successful authentication came from the same source as the failed attempts.

Why this answer

The scenario describes failed logon attempts followed by a successful logon, so the analyst needs the events that directly record those two outcomes. Option A (4624 - An account was successfully logged on) is correct because Event ID 4624 is generated in the Security log whenever a logon succeeds, capturing details such as the account name, logon type, and source workstation that confirm the successful authentication. Option E (4625 - An account failed to log on) is correct because Event ID 4625 is logged for each failed authentication attempt and includes the failure reason, account name, and logon type, which together with 4624 reveals the brute-force-then-success pattern.

Option B (4720 - A user account was created) is not relevant because it records account creation, not authentication activity. Option C (4648 - A logon was attempted using explicit credentials) is not relevant because it logs use of alternate credentials (e.g., RunAs), not the failed/successful logon sequence described. Option D (4776 - The domain controller attempted to validate the credentials for an account) is not relevant because it is a credential-validation event on a domain controller, not the workstation logon success/failure events the analyst needs.

Exam trap

The trap here is that candidates confuse credential-validation events (4776 on the DC, 4648 for explicit credentials) with the endpoint-side success/failure events (4624/4625) that actually answer the question about a workstation's logon sequence.

86
MCQmedium

An analyst is analyzing a suspicious executable file. Using the 'file' command, it returns 'data' instead of 'PE32 executable'. What is the most likely reason?

A.The system is missing the file command database.
B.The file is a legitimate PE file with a different extension.
C.The file is actually a script written in Python.
D.The file has been packed or encrypted to hide its true nature.
AnswerD

Packing or encrypting compresses and obfuscates the executable, so the PE header signature is no longer readable and 'file' reports generic 'data' rather than PE32 executable. This hides the file's true nature from static inspection.

Why this answer

The 'data' result indicates the file's magic bytes do not match known executables, suggesting it might be packed or obfuscated.

87
MCQeasy

An analyst discovers a suspicious service on a Windows host. Which command can be used to query the status and details of services from the command line?

A.services.msc
B.net start
C.sc query
D.tasklist /svc
AnswerC

The sc query command interrogates the Service Control Manager directly, returning the service's current state (running, stopped, paused) plus configuration details such as start type and binary path. This satisfies the requirement to check status and details of a suspicious service from the command line without needing GUI tools.

Why this answer

The 'sc query' command queries the Service Control Manager for the status of a specified service (or all services) directly from the command line, showing state (RUNNING/STOPPED), service type, and exit codes. It is the standard CLI tool for enumerating and inspecting Windows services during host-based forensic analysis. 'sc query type= service state= all' lists every service with its status, making it ideal for spotting suspicious entries.

Exam trap

The trap is confusing GUI tools (services.msc) or process-listing tools (tasklist /svc) with the actual CLI service-query command — candidates pick 'net start' because it's familiar, but it only lists running services, not their configuration.

How to eliminate wrong answers

Option A is wrong because services.msc is a GUI snap-in (Microsoft Management Console) — it is not a command-line tool and cannot be scripted or used in a non-interactive forensic context. Option B is wrong because 'net start' only lists currently running services and can start services; it does not show configuration details like binary paths, start types, or service accounts. Option D is wrong because 'tasklist /svc' lists running processes and maps them to hosted services, but it does not query service configuration, start type, or binary path — it only shows which services are running inside which process.

88
Multi-Selecthard

An analyst is investigating a Linux server and suspects that an attacker has established persistence by modifying system startup scripts. The analyst runs 'ls -la /etc/rc.local' and finds it has been modified recently. Which TWO additional artifacts should the analyst examine to identify other potential persistence mechanisms? (Choose two.)

Select 2 answers
A./etc/passwd
B./etc/cron.d/
C./etc/systemd/system/*.service
D./var/log/auth.log
E./etc/hosts
AnswersB, C

The /etc/cron.d/ directory contains cron job definitions that run on a schedule. Attackers frequently add malicious cron jobs here to maintain persistence by executing payloads at regular intervals. Reviewing this directory can uncover unauthorized scheduled tasks that are not part of the default system configuration.

Why this answer

Attackers on Linux often use systemd service files and cron jobs for persistence because they are executed automatically and can blend in with legitimate system tasks. The /etc/systemd/system/ directory contains custom service units, and /etc/cron.d/ holds cron definitions. Both are critical to examine when hunting for persistence, as they allow code execution without user interaction.

Exam trap

The trap here is focusing on log files or user account files for persistence, when the question specifically points to startup scripts and scheduled tasks.

89
MCQmedium

An analyst is reviewing logs on a Windows 10 host that is suspected of being compromised. The analyst runs 'wevtutil qe Security /q:"*[System[(EventID=4688)]]" /f:text' and sees that a process named 'powershell.exe' was launched by 'winword.exe' with the command line 'powershell -nop -w hidden -enc SQBFAFgA...'. Which type of malicious activity does this most likely indicate?

A.A macro-based document exploit spawning an encoded PowerShell payload
B.A user manually running a PowerShell script for administrative purposes
C.A legitimate Office add-in that uses PowerShell for automation
D.A scheduled task created by Windows Update to install patches
AnswerA

The parent process winword.exe launching an encoded, hidden PowerShell command is a classic sign of a malicious macro in an Office document executing a stager. The -enc flag indicates Base64-encoded commands, often used to obfuscate payloads. This combination is a strong indicator of a phishing document exploit leading to code execution.

Why this answer

The parent-child relationship between winword.exe and powershell.exe with encoded, hidden arguments is a well-known indicator of a malicious macro exploit. Attackers often use Office documents to launch PowerShell stagers that download or execute further payloads. This pattern is commonly seen in phishing campaigns and is a key detection point for endpoint security tools.

Exam trap

The trap here is assuming that any PowerShell execution from Office is benign automation, overlooking the malicious flags and encoded command.

90
MCQhard

A security analyst is examining a Windows 10 endpoint suspected of compromise. The analyst runs `wmic process get name,processid,executablepath,parentprocessid` and observes a process named `lsass.exe` with PID 1234 and executable path `C:\Windows\Temp\lsass.exe`. The legitimate lsass.exe should reside in `C:\Windows\System32`. Which of the following is the MOST likely explanation?

A.The output is a false positive because wmic sometimes reports incorrect executable paths for system processes.
B.A malware sample is masquerading as lsass.exe to evade detection by name-based monitoring.
C.The system is experiencing a file system corruption that moved lsass.exe to a temporary folder.
D.The process is a legitimate instance of lsass.exe that was moved by a Windows Update.
AnswerB

Attackers commonly name malicious executables after legitimate system processes like lsass.exe to blend in. Placing the binary in a non-standard location such as C:\Windows\Temp is a strong indicator of compromise. The analyst should immediately collect the file, hash it, and investigate its origin and behavior, as this is a classic masquerading technique.

Why this answer

Legitimate Windows system processes run from specific system directories, such as System32. When a process named lsass.exe is found in a non-standard location like C:\Windows\Temp, it is almost certainly malware attempting to hide by using a trusted process name. The analyst should treat this as a compromise, isolate the host, and perform further forensics including file hash analysis and persistence checks.

Exam trap

The trap here is assuming that a process named lsass.exe is always the legitimate Windows process, without verifying its executable path.

91
MCQmedium

During a host-based analysis, a Windows system is found to have a suspicious service that starts automatically. Which command-line tool can be used to query the status and configuration of services, particularly to identify non-standard service names or paths?

A.sc query
B.services.msc
C.tasklist /svc
D.net start
AnswerA

The sc query command interrogates the Windows Service Control Manager, returning each service's status, start type and binary path. This directly satisfies the need to spot non-standard service names or executable paths during host-based analysis, since the SCM holds the authoritative configuration.

Why this answer

The 'sc query' command queries the Service Control Manager for service status and configuration, and with 'sc qc' it reveals the binary path, start type, and service account — exactly what's needed to spot non-standard service names or paths. It works from the command line, making it suitable for scripted forensic triage. Analysts use 'sc query state= all' to enumerate all services and 'sc qc <name>' to inspect suspicious ones.

Exam trap

The trap is confusing service enumeration (sc query) with process-to-service mapping (tasklist /svc) or GUI tools (services.msc) — candidates pick tasklist /svc because it shows services, but it lacks configuration details like binary path.

How to eliminate wrong answers

Option B is wrong because services.msc is a GUI tool, not a command-line utility, and cannot be easily scripted or used in automated forensic collection. Option C is wrong because tasklist /svc only maps running processes to hosted services — it does not show service configuration, binary paths, or start types, so it cannot identify non-standard paths. Option D is wrong because 'net start' only lists running services and can start them; it does not reveal configuration details like ImagePath or start type.

92
MCQmedium

A SOC analyst is reviewing a Windows 10 endpoint that is suspected of being compromised by malware that hides its network connections. The analyst runs 'netstat -anob' on the live system but does not see any suspicious outbound connections. Which Windows artifact should the analyst examine next to identify network connections that may have been hidden from the live API?

A.The SRUM database (SRUDB.dat) parsed with a tool such as srum-dump
B.The Amcache.hve registry hive parsed with AmcacheParser
C.The ShimCache (AppCompatCache) entries in the SYSTEM hive
D.The Windows Prefetch files parsed with PECmd
AnswerA

SRUM (System Resource Usage Monitor) records per-application network usage and bytes sent/received over time, stored in SRUDB.dat. Malware that hooks live APIs to hide from netstat still generates SRUM entries because the ESE database is populated by the ESE-based SRUM service, not by the APIs the malware hooks. Parsing it can reveal a process that communicated externally even when live tooling shows nothing.

Why this answer

SRUM maintains a rolling record of per-application resource usage, including bytes sent and received and network interface activity, in the SRUDB.dat ESE database. Because it is populated by the SRUM service rather than by the APIs malware commonly hooks to hide from netstat or GetTcpTable, it can surface external communications that live commands miss. Parsing SRUM therefore gives the analyst network evidence the live system concealed.

Exam trap

The trap here is assuming that if netstat shows nothing suspicious, the host made no suspicious network connections, when API-hooking malware can hide from live queries while SRUM still logs the traffic.

93
MCQeasy

A security analyst is reviewing Windows Event Logs to determine if a user account was recently created on a compromised host. Which Windows Event ID should the analyst look for in the Security log to identify user account creation events?

A.Event ID 4672
B.Event ID 4720
C.Event ID 4624
D.Event ID 4625
AnswerB

Event ID 4720 is generated when a new user account is created. It includes the target username and the subject (the account that performed the creation). This is the correct event ID to identify user account creation activity, which is a common persistence technique used by attackers to maintain access to a compromised system.

Why this answer

Windows Security Event ID 4720 is specifically logged when a user account is created. It contains fields such as TargetUserName (the new account) and SubjectUserName (the account that created it). This event is critical for detecting unauthorized account creation, which attackers often use for persistence.

Other event IDs like 4624 (logon) or 4625 (failed logon) do not indicate account creation.

Exam trap

The trap here is confusing logon-related event IDs (such as 4624 or 4625) with account management events like 4720.

94
MCQmedium

An analyst is examining a Windows system for evidence of malware that maintains persistence by modifying the Image File Execution Options (IFEO) registry key. Which of the following best describes how this technique works?

A.The malware adds a new service that runs under the context of the SYSTEM account.
B.The malware sets the 'Debugger' value for a legitimate process, causing the debugger to execute instead of the intended process.
C.The malware creates a shortcut in the Startup folder to launch automatically.
D.The malware modifies the 'Shell' value in the Winlogon registry key to execute on user logon.
AnswerB

IFEO allows developers to attach a debugger to a process. Malware can abuse this by setting the 'Debugger' value under the IFEO key for a legitimate process (e.g., notepad.exe) to point to a malicious executable. When the legitimate process is launched, the malicious 'debugger' runs instead, achieving persistence and potentially privilege escalation.

Why this answer

Image File Execution Options (IFEO) is a registry key that allows setting a debugger for a specific executable. Malware abuses this by setting the Debugger value to its own binary, so when the targeted process is launched, the malicious debugger runs instead. This provides persistence and can be used to hijack trusted processes, making detection challenging.

Exam trap

The trap here is confusing IFEO with other persistence mechanisms like services or Winlogon; IFEO specifically uses the Debugger value to redirect execution.

95
MCQmedium

An analyst is reviewing Windows Event Logs and finds Event ID 4648. What does this event typically indicate?

A.A failed logon attempt
B.An account creation event
C.A successful logon event
D.A logon using explicit credentials
AnswerD

Event ID 4648 is generated when a process explicitly supplies alternate credentials for a logon, such as RunAs or scheduled tasks using stored credentials. It records the target account and the subject initiating it, distinguishing explicit credential use from ordinary interactive logons.

Why this answer

Windows Security Event ID 4648 is logged when a process attempts an explicit-credential logon — that is, when a user or service supplies alternate credentials (via runas, New-PSSession -Credential, or similar) rather than using the current session's token. It records the account that requested the logon and the account whose credentials were used.

Exam trap

200-201 often tests the confusion between 4648 (explicit credentials) and 4624 (successful logon) — candidates pick 4624 because both involve credentials, missing that 4648 specifically flags alternate-credential use.

How to eliminate wrong answers

Option A is wrong because failed logon attempts are Event ID 4625 (with substatus codes explaining the failure reason). Option B is wrong because account creation is Event ID 4720 (and 4722 for enablement). Option C is wrong because a successful interactive logon is Event ID 4624, which logs the logon type (2, 3, 10, etc.) and the resulting session.

96
Multi-Selectmedium

A threat hunter is examining a Linux web server that is suspected of being compromised. The hunter wants to identify suspicious processes that may be communicating with external command-and-control infrastructure and to understand what files those processes have open. Which TWO artifacts or commands should the hunter use to accomplish these goals? (Choose two.)

Select 2 answers
A.Review /var/log/secure for failed authentication attempts
B.Run 'ss -tunap' to enumerate listening and established sockets with their owning processes
C.Inspect /proc/<pid>/net/tcp and /proc/<pid>/fd to map network sockets and open file descriptors for each process
D.Parse the wtmp and btmp binary logs with the 'last' command
E.Examine /etc/crontab for scheduled jobs
AnswersB, C

The ss utility with -tunap lists TCP, UDP, and Unix sockets, including established connections and the process name and PID that owns each socket. This directly exposes outbound connections to external addresses and identifies the responsible process, which is precisely what the hunter needs to spot C2 communication on the compromised web server.

Why this answer

Mapping C2 traffic and open files on Linux requires live process-to-socket visibility. The ss command with -tunap enumerates sockets together with owning processes, exposing established outbound connections. The /proc filesystem complements this by exposing per-process socket inodes and open file descriptors, letting the hunter pivot from a suspicious PID to the exact files and connections it holds.

Together they reveal both the communication channel and the process context.

Exam trap

The trap here is gravitating toward log files like /var/log/secure or cron because they are familiar, when the scenario asks specifically about live process network and file-descriptor visibility.

97
MCQmedium

An analyst is investigating a Linux web server that is exhibiting unusual outbound network traffic. The analyst runs 'lsof -i' and notices that the process 'apache2' has an established connection to an external IP address on port 4444. Further investigation shows that a file named 'update.php' in the web root contains obfuscated code. Which type of compromise does this most likely represent?

A.A web shell providing remote command and control
B.A scheduled backup process transferring data to a remote server
C.A legitimate plugin communicating with an update server
D.A misconfigured Apache module causing unexpected connections
AnswerA

A web shell is a malicious script uploaded to a web server that allows remote attackers to execute commands and maintain persistence. The outbound connection on a non-standard port like 4444 (often used by Metasploit) from the web server process suggests a reverse shell initiated by the web shell. The obfuscated PHP file is a common indicator.

Why this answer

The combination of an outbound connection from the web server process on a common reverse shell port (4444) and an obfuscated PHP file in the web root is a classic indication of a web shell. Attackers use web shells to execute commands and maintain access, often leading to data exfiltration or further network compromise.

Exam trap

The trap here is assuming the connection is benign because it originates from a legitimate process, ignoring the suspicious port and obfuscated file.

98
MCQhard

A security analyst is investigating a Linux server that is exhibiting unusual outbound network traffic. The analyst runs 'netstat -tulpn' and observes a listening service on TCP port 4444, but the process name is 'sshd'. The analyst knows that SSH normally listens on port 22. Which of the following is the most likely explanation for this finding?

A.The server is running an SSH honeypot on port 4444 to attract attackers.
B.A backdoor or reverse shell is masquerading as the SSH daemon.
C.The SSH daemon is configured to use port 4444 for SFTP transfers only.
D.The SSH daemon has been reconfigured to listen on port 4444 for security through obscurity.
AnswerB

Attackers often name malicious processes after legitimate services like 'sshd' to avoid detection. Port 4444 is commonly used by Metasploit and other penetration testing tools for reverse shells. The combination of an unexpected port and a process name that does not match the expected behavior (SSH on port 22) strongly indicates a backdoor or reverse shell masquerading as sshd.

Why this answer

The presence of a service named 'sshd' listening on port 4444, especially with unusual outbound traffic, is a red flag for a backdoor or reverse shell. Attackers frequently use common ports like 4444 for command-and-control and name their processes after legitimate services to blend in. Legitimate SSH should listen on port 22 unless explicitly changed, and such a change would be documented.

Exam trap

The trap here is assuming that a process with a familiar name like 'sshd' is benign, but attackers can easily rename their malicious binaries.

99
MCQeasy

An analyst is reviewing Windows Event Logs and sees Event ID 4625. What does this event indicate?

A.Credential validation was attempted
B.An account logon failed
C.An account was created
D.An account was successfully logged on
AnswerB

Windows Event ID 4625 is logged in the Security log whenever a logon attempt fails, recording the account, source workstation and failure reason. It directly satisfies the stem's requirement to identify what this event indicates.

Why this answer

Event ID 4625 in the Security log indicates a failed logon attempt. This is often used to detect brute-force attacks or unauthorized access attempts.

100
MCQmedium

An analyst is investigating a Windows system where a suspicious executable is running. Using Process Explorer, the analyst observes that the process 'svchost.exe' has a parent process of 'cmd.exe'. What is the significance of this parent-child relationship?

A.It shows that svchost.exe is a critical system process and is safe
B.It indicates that svchost.exe is likely malicious, as it should be spawned by services.exe
C.It suggests that svchost.exe is a child of explorer.exe, which is normal
D.It is normal behavior; svchost.exe often has cmd.exe as parent
AnswerB

Legitimate svchost.exe instances are launched by services.exe, so a cmd.exe parent reveals a process masquerading under that name — a common malware technique. The anomalous parentage, not the filename itself, is the indicator satisfying the scenario's suspicious-executable constraint.

Why this answer

Legitimate svchost.exe processes are spawned by services.exe, not cmd.exe. A parent of cmd.exe indicates that svchost.exe was launched manually, which is abnormal and suggests malicious activity.

101
MCQhard

A security analyst is examining a Windows 10 host that is suspected of being compromised. The analyst runs `wmic process get name,processid,executablepath,commandline` and notices a process named `svchost.exe` with an executable path of `C:\Users\Public\svchost.exe`. Which conclusion is most accurate?

A.The process is a legitimate svchost.exe because the name matches the system process.
B.The process is a legitimate svchost.exe running from a non-standard location due to a Windows update.
C.The process is likely malware masquerading as svchost.exe.
D.The process is likely a legitimate svchost.exe that was copied to the Public folder by a user.
AnswerC

Legitimate svchost.exe processes reside in %SystemRoot%\System32. An instance running from C:\Users\Public is a strong indicator of malware, as attackers often name their binaries after system processes and place them in user-writable directories to evade detection. The analyst should investigate further, such as checking digital signatures and parent process.

Why this answer

Legitimate svchost.exe always runs from %SystemRoot%\System32\svchost.exe. An instance with an executable path in C:\Users\Public is almost certainly malware masquerading as a system process. Attackers use this technique to blend in with normal system activity.

Analysts should verify the digital signature, parent process, and loaded modules to confirm maliciousness.

Exam trap

The trap here is trusting the process name and assuming it is legitimate, when the executable path is the key indicator of masquerading.

102
Multi-Selectmedium

An incident responder is analyzing a Windows machine for evidence of malware persistence. Which TWO registry keys are commonly abused to achieve automatic execution at user logon?

Select 2 answers
A.HKLM\Software\Microsoft\Windows\CurrentVersion\Run
B.HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
C.HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
E.HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
AnswersA, D

The HKLM Run key applies machine-wide, launching listed programs at logon for every user. Writing to it requires administrative privileges, so malware using this location typically arrives via elevation or an installer, giving persistence across all accounts.

Why this answer

Options A and D are correct because HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run are the canonical Run keys that Windows automatically processes at user logon, launching any listed program for all users (HKLM) or the specific user (HKCU), which is why malware commonly writes here for persistence. Option C (RunOnce) also triggers at logon but is designed for one-time execution and the value is deleted after it runs, so it is not the standard persistent automatic-execution key the question targets. Option B (AppInit_DLLs) is a DLL-injection mechanism loaded into processes using User32.dll, not a logon-triggered program launcher.

Option E (Image File Execution Options) is abused for debugger hijacking or executable redirection, not for automatic execution at logon.

Exam trap

The trap is confusing RunOnce (one-time execution) with Run (persistent execution), or picking AppInit_DLLs which is a different persistence type not tied to logon.

103
MCQmedium

An analyst is examining a Linux system for persistence mechanisms. Which of the following files should be reviewed to detect cron-based persistence?

A./var/log/auth.log
B./etc/passwd
C./home/user/.bash_history
D./var/spool/cron/crontabs
AnswerD

User crontab entries are stored under /var/spool/cron/crontabs, one file per user, so reviewing this directory reveals scheduled jobs an attacker added for persistence. System-wide schedules live in /etc/crontab and /etc/cron.d, making this the correct user-level location.

Why this answer

The correct answer is /var/spool/cron/crontabs because this directory stores user-specific cron jobs on Debian-based Linux systems. Attackers often add malicious entries here to maintain persistence by scheduling recurring tasks. Reviewing this directory reveals unauthorized scheduled jobs that could execute malware or reverse shells at regular intervals.

Exam trap

The trap here is confusing log files or user account files with actual persistence configuration files; candidates might pick /var/log/auth.log because it logs cron activity, but the question asks for the file to review to detect the persistence mechanism itself.

How to eliminate wrong answers

Option A is wrong because /var/log/auth.log contains authentication logs, not cron job definitions; it may show cron execution but not the persistence mechanism itself. Option B is wrong because /etc/passwd stores user account information, not scheduled tasks; while attackers may add rogue users, that is a different persistence method. Option C is wrong because /home/user/.bash_history records interactive shell commands, not cron jobs; it might show an attacker creating a cron job, but the actual persistence file is elsewhere.

104
MCQmedium

During an incident response, an analyst checks for persistence mechanisms and finds an entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. What is the most likely purpose of this registry key?

A.It lists recently accessed documents.
B.It specifies programs to run automatically at user logon.
C.It stores user interface settings for the current user.
D.It controls Windows Defender exclusions.
AnswerB

The Run key under HKCU executes listed programs automatically each time that user logs on, giving malware persistence without administrative rights. This satisfies the stem's persistence mechanism: the entry survives reboots and relaunches the payload at user logon, unlike one-time execution or system-wide services requiring elevation.

Why this answer

It specifies programs to run automatically at user logon is correct because the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key is a common autostart location that executes programs when the user logs in. Attackers often use this key for persistence to ensure their malware runs after a reboot or logon.

Exam trap

200-201 often tests the knowledge of common persistence mechanisms. Candidates might confuse the Run key with other registry keys that store user settings or recent documents, but the Run key is specifically for autostart programs.

How to eliminate wrong answers

Option A is wrong because recently accessed documents are tracked in the RecentDocs key or via jump lists, not in the Run key. Option C is wrong because user interface settings are stored in various keys under HKCU\Software, but not specifically in the Run key. Option D is wrong because Windows Defender exclusions are stored in a different registry location, such as HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions.

105
MCQmedium

An analyst suspects a Windows workstation is beaconing to a command-and-control server. The host's DNS cache contains an entry for a domain that resolves to an IP address, but the analyst cannot find any active network connection or process associated with that domain. Which Windows artifact should the analyst examine to determine whether a process previously resolved this domain and when?

A.The Windows Firewall log at %systemroot%\system32\LogFiles\Firewall\pfirewall.log
B.The DNS Client event log (Microsoft-Windows-DNS-Client/Operational)
C.The Application event log
D.The System event log
AnswerB

The Microsoft-Windows-DNS-Client/Operational log records DNS query events, including the process name, query name, query type, and timestamp. In this scenario, it can reveal which process resolved the suspicious domain and when, even if the connection is no longer active. This directly addresses the need to correlate a domain with a process and time.

Why this answer

The Microsoft-Windows-DNS-Client/Operational log is designed to record DNS client query events, including the query name, query type, timestamp, and the process that initiated the query. When a host is beaconing, the DNS cache may only show the resolved IP, but the operational log can show which process resolved the domain and when, enabling the analyst to link the beaconing behavior to a specific executable.

Exam trap

The trap here is assuming that the DNS cache or firewall log provides process attribution and timestamps for domain resolution, when only the DNS Client operational log records that level of detail.

106
MCQmedium

Which Linux log file is most appropriate for reviewing failed SSH login attempts?

A./var/log/auth.log
B./var/log/messages
C./var/log/kern.log
D./var/log/syslog
AnswerA

On Debian and Ubuntu systems, the SSH daemon writes authentication events, including failed login attempts, to /var/log/auth.log via the authpriv facility. This makes it the appropriate file for reviewing failed SSH logins on those distributions.

Why this answer

/var/log/auth.log is the standard Linux log file that records authentication events, including successful and failed SSH login attempts, sudo usage, and PAM-related messages. On Debian/Ubuntu systems, sshd logs authentication failures here via the authpriv facility. This makes it the most appropriate file for reviewing failed SSH logins.

Exam trap

200-201 often tests the confusion between general system logs (syslog, messages) and dedicated authentication logs (auth.log, secure) — candidates may pick syslog because it 'contains everything' when auth.log is the precise answer for SSH failures.

How to eliminate wrong answers

Option B is wrong because /var/log/messages is a general system log on some distributions (like RHEL/CentOS) but does not specifically capture authentication events — SSH failures are typically in /var/log/secure on those systems. Option C is wrong because /var/log/kern.log records kernel messages, not user authentication or SSH login attempts. Option D is wrong because /var/log/syslog is a general system log that may contain some SSH messages but is not the dedicated authentication log; auth.log is more specific and reliable for failed logins.

107
MCQmedium

An analyst is examining a PE file and notices that the 'TimeDateStamp' in the optional header is 0x00000000. What does this suggest?

A.The timestamp has been deliberately erased or not set, possibly to avoid forensic analysis.
B.The file is digitally signed.
C.The file was compiled on January 1, 1970 (Unix epoch).
D.The file is a DLL rather than an executable.
AnswerA

A zero TimeDateStamp means the PE compiler timestamp was never written or was overwritten. Legitimate builds normally carry a real compilation time, so this absence suggests deliberate erasure to hinder timeline correlation during forensic analysis.

Why this answer

A timestamp of zero often indicates the linker did not set it, which is common for malware or files compiled with certain tools that omit the timestamp.

108
MCQeasy

A junior analyst is asked to review a Linux server for evidence of unauthorized access. They want to see a chronological record of authentication-related messages, including successful and failed logins, generated by the system's authentication services. Which file should the analyst examine?

A./var/log/dpkg.log
B./var/log/auth.log
C./var/log/boot.log
D./var/log/kern.log
AnswerB

On Debian and Ubuntu systems, /var/log/auth.log is the primary file where the authentication subsystem writes messages about successful and failed logins, sudo usage, and PAM events. Reviewing it gives the analyst the chronological authentication record they need to spot unauthorized access attempts on the server.

Why this answer

Authentication-related messages on Debian and Ubuntu are written to /var/log/auth.log by services such as sshd, sudo, and PAM. Because this file captures both successful and failed login attempts in chronological order, it is the correct source for reviewing unauthorized access on the server.

Exam trap

The trap here is assuming all Linux distributions use the same authentication log path, when Red Hat-based systems instead write to /var/log/secure and some use journald.

109
MCQeasy

A Linux analyst wants to identify all listening TCP ports on a system. Which command is most appropriate?

A.netstat -an
B.ss -tlnp
C.lsof -i
D.ps aux
AnswerB

The `ss -tlnp` command combines `-t` for TCP sockets, `-l` for listening state, `-n` for numeric ports, and `-p` for owning processes, directly satisfying the requirement to enumerate every listening TCP port on the Linux host.

Why this answer

ss -tlnp shows listening TCP sockets with process info.

110
MCQeasy

A junior analyst is triaging a Windows workstation that users report is running slowly. The analyst suspects a malicious process is persisting by masquerading as a legitimate Windows service. Which built-in Windows tool should the analyst use to view services, their binary paths, and their current state without installing additional software?

A.The Services console (services.msc)
B.Performance Monitor (perfmon.msc)
C.Task Manager's Processes tab
D.Event Viewer's Application log
AnswerA

The Services console lists every installed Windows service along with its display name, start type, status, and, under the General tab or via the registry, the path to the service binary. This lets the analyst spot a service whose ImagePath points to an unusual directory or executable, which is a classic masquerading persistence technique. It requires no third-party tools.

Why this answer

The Services console (services.msc) is the native Windows management interface that enumerates all installed services and exposes each one's display name, status, start type, and the path to its executable. By reviewing those paths, the analyst can identify a service whose binary resides in an unexpected location, which is a common masquerading persistence method, without deploying any additional tooling.

Exam trap

The trap here is equating Task Manager's process list with a full service inventory, when Task Manager does not reliably show every service's configured binary path or start type.

111
MCQmedium

An analyst is investigating a Linux host and runs 'cat /proc/1234/cmdline'. What information does this provide?

A.The memory map of the process
B.The command line and arguments used to start the process
C.The environment variables of the process
D.The current working directory of the process
AnswerB

Reading `/proc/<pid>/cmdline` returns the exact command line and arguments that launched process 1234, with arguments separated by null bytes. This directly satisfies the scenario's requirement to identify how the process was started on the Linux host, exposing suspicious flags or scripts an attacker used.

Why this answer

The file /proc/1234/cmdline is a pseudo-file exposed by the Linux kernel's procfs for the process with PID 1234. Reading it returns the exact command line and arguments that were passed to execve() when the process was started, with arguments separated by NUL bytes. This is why 'cat' often shows the arguments run together — the NUL separators are not rendered as visible characters.

Exam trap

The trap here is confusing the various /proc/PID pseudo-files — candidates often pick environ or maps because they vaguely remember 'something about process info in /proc' without mapping the exact filename to the exact data.

How to eliminate wrong answers

Option A is wrong because the memory map of a process is exposed via /proc/1234/maps, not cmdline. Option C is wrong because environment variables are exposed via /proc/1234/environ. Option D is wrong because the current working directory is exposed via the /proc/1234/cwd symbolic link (readable with ls -l or readlink).

112
MCQhard

An analyst is examining a suspicious PE file. The file's entropy is very high (close to 8.0) and the import table is almost empty. What does this indicate?

A.The file is likely packed or obfuscated
B.The file is a DLL file
C.The file is a standard Windows executable with many imports
D.The file has been digitally signed
AnswerA

High entropy and few imports indicate packing.

Why this answer

High entropy close to 8.0 indicates that the file's data is highly random, which is characteristic of packed or encrypted content. An almost empty import table suggests that the file does not statically import many functions, common in packed malware that resolves imports dynamically at runtime. Together, these strongly indicate packing or obfuscation.

Exam trap

200-201 often tests the interpretation of entropy and import tables, and candidates may think high entropy always means malicious, but it can also indicate legitimate packing; however, combined with empty imports, it strongly suggests malicious packing.

How to eliminate wrong answers

Option B is wrong because being a DLL file does not inherently cause high entropy or an empty import table; DLLs can have normal entropy and imports. Option C is wrong because a standard Windows executable with many imports would have a populated import table and lower entropy. Option D is wrong because digital signing does not affect entropy or import table; signed files can still have normal characteristics.

113
MCQhard

An analyst uses Volatility's pstree plugin on a memory dump. The output shows that process 'winlogon.exe' has a child process 'cmd.exe' that is not typical. What is the most likely explanation?

A.An attacker may have used Sticky Keys or similar persistence.
B.A user is running a command prompt remotely.
C.A scheduled task is running.
D.The system is performing a normal update.
AnswerA

Sticky Keys (sethc.exe) can be replaced with cmd.exe to provide a command prompt at login.

Why this answer

In a normal Windows session, winlogon.exe spawns userinit.exe (which then launches explorer.exe) — it should never spawn cmd.exe. A cmd.exe child of winlogon.exe is a classic indicator of the Sticky Keys (sethc.exe) or Utilman accessibility-feature backdoor, where an attacker replaces the binary with cmd.exe so that pressing Shift five times at the logon screen yields a SYSTEM-level shell. This persistence technique survives reboots and is frequently observed in memory forensics via pstree output.

Exam trap

The trap here is assuming any cmd.exe in memory is benign user activity; candidates must recognize that the parent process (winlogon.exe) is the anomaly, not the mere presence of cmd.exe.

How to eliminate wrong answers

Option B is wrong because a remote command prompt would appear as a child of services.exe, svchost.exe, or wsmprovhost.exe (WinRM), not winlogon.exe, and would not require the accessibility-binary swap. Option C is wrong because scheduled tasks execute under taskeng.exe or svchost.exe (Task Scheduler service), producing a different parent-child relationship. Option D is wrong because Windows Update runs under TrustedInstaller.exe or the Windows Update service (wuauclt.exe), never as a cmd.exe child of winlogon.exe.

114
MCQhard

During a forensic examination of a Linux system, an analyst wants to check for persistence mechanisms. Which file or directory should be examined to find user-specific cron jobs that may have been added by an attacker?

A./etc/cron.hourly/
B./etc/cron.d/
C./etc/crontab
D./var/spool/cron/crontabs/
AnswerD

User-specific crontab entries are stored under /var/spool/cron/crontabs/ (or /var/spool/cron/ on some distributions), one file per user. Examining this directory directly reveals attacker-added scheduled jobs, satisfying the requirement to identify user-specific cron persistence rather than system-wide schedules held in /etc/crontab or /etc/cron.d/.

Why this answer

User-specific cron jobs are stored in /var/spool/cron/crontabs/ (on Debian-based systems) or /var/spool/cron/ (on Red Hat-based systems). Each user has a file named after their username containing their cron jobs. Attackers often add entries here for persistence.

The other locations are for system-wide cron jobs.

Exam trap

200-201 often tests the distinction between system-wide cron locations and user-specific crontabs, and the exact path for user crontabs on different Linux distributions.

How to eliminate wrong answers

Option A is wrong because /etc/cron.hourly/ contains scripts run hourly by the system, not user-specific cron jobs. Option B is wrong because /etc/cron.d/ contains system cron jobs with additional fields (like user), but not user-specific crontabs. Option C is wrong because /etc/crontab is the system crontab file that defines run-parts for hourly, daily, etc., and is not user-specific.

115
Multi-Selectmedium

An analyst is investigating a Windows host that likely has malware persistence via the registry. Which TWO registry hives are commonly used to store Run keys for user logon persistence? (Select 2)

Select 2 answers
A.HKEY_CLASSES_ROOT\*\shell
B.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
C.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppInit_DLLs
D.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
E.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
AnswersB, E

The HKLM Run key executes listed programs at logon for every user on the host, making it a machine-wide persistence location. This satisfies the stem's user logon persistence constraint, since malware written here survives reboots and affects all accounts.

Why this answer

The Run keys under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run are standard locations where Windows executes programs automatically at user logon. Malware commonly writes entries to these keys to achieve persistence, making them critical for host-based analysis.

Exam trap

Cisco often tests the distinction between Run keys (user logon persistence) and other registry locations like AppInit_DLLs or Services, so candidates must know that only the Run paths under HKLM and HKCU are correct for this specific persistence method.

116
MCQmedium

In Windows, prefetch files (C:\Windows\Prefetch\*.pf) are used by the system to speed up application loading. How can an analyst leverage prefetch files during host-based analysis?

A.They provide evidence of file execution, including frequency and timestamps.
B.They store network connection logs.
C.They store registry keys modified by the application.
D.They contain the contents of the running process memory.
AnswerA

Prefetch files record each executable's name, run count and last-run timestamps, so analysts can confirm that a program executed on the host, how often, and when. This directly satisfies the need to establish file execution evidence during host-based analysis.

Why this answer

Prefetch files in Windows record metadata about application launches, including the executable path, run count, and last run timestamp. During host-based analysis, an analyst can examine these .pf files to determine which executables have been executed, how often, and when, providing crucial evidence of file execution activity.

Exam trap

Cisco often tests the specific purpose of prefetch files versus other forensic artifacts, and the trap here is confusing prefetch files with memory dumps or registry logs, leading candidates to select options that describe unrelated Windows components.

How to eliminate wrong answers

Option B is wrong because prefetch files do not store network connection logs; network connection logs are typically found in Windows Event Logs (e.g., Security log with Event ID 5156) or firewall logs. Option C is wrong because prefetch files do not store registry keys modified by the application; registry modifications are tracked in the Registry hive files (e.g., NTUSER.DAT, SYSTEM, SOFTWARE) and can be analyzed via tools like RegRipper. Option D is wrong because prefetch files do not contain the contents of the running process memory; process memory contents are captured in memory dumps (e.g., .dmp files) or via forensic tools like Volatility.

117
Multi-Selectmedium

An analyst is investigating a Windows host for malware persistence. Which TWO registry locations are commonly abused for persistence by modifying the 'Run' key? (Select TWO)

Select 2 answers
A.HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
B.HKLM\Software\Microsoft\Windows\CurrentVersion\Run
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
D.HKLM\System\CurrentControlSet\Services
E.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
AnswersB, C

The HKLM Run key executes programs at logon for all users and needs administrative privileges to modify. Malware with elevated access writes here for system-wide persistence, satisfying the scenario's requirement for a commonly abused Run-key location on the Windows host.

Why this answer

Both HKLM and HKCU Run keys are commonly used for persistence.

118
MCQhard

An analyst is investigating a Windows workstation that exhibits suspicious outbound network traffic. The analyst suspects a malicious process is injecting code into a legitimate process. Which of the following Windows Event Log sources would MOST likely contain evidence of process creation and image loading that could reveal the injection?

A.System
B.Security
C.Application
D.Microsoft-Windows-Sysmon/Operational
AnswerD

Sysmon logs detailed process creation events (Event ID 1) and image loaded events (Event ID 7), which can show if a legitimate process loaded an unexpected DLL or if a process was created with suspicious parameters. This is the most direct source for detecting code injection, as it captures the loading of images into processes.

Why this answer

Sysmon, when installed, provides extensive logging of process creation and image loads, which are critical for identifying code injection. The Microsoft-Windows-Sysmon/Operational log contains Event ID 7 for image loads, allowing analysts to see if a process loaded an unexpected DLL, a common sign of injection.

Exam trap

The trap here is assuming that the Security log's process creation events are sufficient, but they lack image load details that are essential for detecting injection.

← PreviousPage 2 of 2 · 118 questions total

Ready to test yourself?

Try a timed practice session using only Host-Based Analysis questions.