200-201 Host-Based Analysis Practice Question
During forensic analysis of a Windows host, an analyst finds a file in C:\Windows\Prefetch with the name 'MALWARE.EXE-3F2A1B0C.pf'. Which type of information can be extracted from this prefetch file to assist the investigation?
⚠ Common exam trap
The trap is assuming prefetch captures command-line arguments or registry changes — it does not; those come from process-creation auditing and registry artifacts respectively, and candidates often conflate forensic artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The number of times the executable has been run and the last execution timestamp
Windows Prefetch files (.pf) store execution metadata for applications, including the run count and the last time the executable was executed (plus up to the last eight run timestamps on some Windows versions). This makes them a primary artifact for establishing whether and when malware ran on a host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The number of times the executable has been run and the last execution timestamp
Why this is correct
Prefetch files record run count and last-write execution timestamps for each executable, letting the analyst establish when MALWARE.EXE last ran and how frequently. This supports timeline reconstruction, though it does not reveal command-line arguments or network connections.
- ✗
The file's SHA256 hash and digital signature status
Why it's wrong here
Prefetch files record execution metadata such as run count, timestamps and referenced file paths and volumes, not cryptographic hashes or Authenticode signature status. It is tempting because hashes and signatures are useful forensic artefacts, but those come from tools like sigcheck or Get-FileHash, not from prefetch parsing.
- ✗
The registry keys modified by the executable during execution
Why it's wrong here
Prefetch captures loaded modules, file and volume references, and execution timestamps, but not the registry keys an executable writes. It is tempting because registry changes are valuable during malware analysis, yet those are recovered from registry hives or tools such as RegRipper, not from .pf files.
- ✗
The command-line arguments used when the executable was launched
Why it's wrong here
Prefetch records execution metadata — load times, run count, and referenced file paths — but not process command lines, which live in ShimCache, Amcache, or Event ID 4688. It tempts because prefetch does capture launch context, yet command-line arguments specifically require those other artefacts; prefetch would be the right source for proving the binary executed and when.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.