200-201 Host-Based Analysis Practice Question
During incident response on a Linux server, an analyst runs 'ss -tlnp' and sees an SSH service listening on a non-standard high port. Which step should the analyst take next to investigate potential unauthorized access?
⚠ Common exam trap
The trap here is that candidates may focus on persistence mechanisms (like cron jobs) or process listing instead of the immediate authentication evidence, confusing the step of verifying unauthorized access with later stages of incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Examine /var/log/auth.log for successful logins.
The correct next step is to examine /var/log/auth.log because it records authentication events, including successful SSH logins. Since the SSH service is listening on a non-standard high port, an attacker may have modified the SSH configuration to evade detection and then logged in. Reviewing auth.log will reveal if any unauthorized successful logins occurred, along with source IPs, usernames, and timestamps, which are critical for determining the scope of the incident. This directly addresses the potential unauthorized access indicated by the unusual listening port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review the bash history of root user.
Why it's wrong here
Bash history records interactive commands, not the process or network context of the listening SSH daemon, so it cannot confirm whether the high port was authorised. It is tempting because history reveals attacker actions, and would be correct when tracing commands executed after a confirmed compromise.
- ✗
Check /etc/crontab for malicious scheduled tasks.
Why it's wrong here
Crontab entries reveal persistence mechanisms, not the identity or parent of the process currently bound to that high port, so the active intrusion stays unexamined. Checking scheduled tasks is tempting because attackers commonly establish cron-based persistence, and it would be correct once the listening process is identified and persistence hunting begins.
- ✗
Run 'ps aux' to list all processes.
Why it's wrong here
Listing processes with 'ps aux' shows running commands but not which process owns the listening socket, so the suspicious SSH listener remains unidentified. It is tempting because process enumeration is a standard triage step, and it would be the right choice when hunting for anomalous binaries or resource-hogging processes rather than mapping a port to its owning PID.
- ✓
Examine /var/log/auth.log for successful logins.
Why this is correct
A non-standard SSH port suggests possible backdoor or compromised service, so the analyst must determine whether anyone authenticated successfully. /var/log/auth.log records SSH authentication events, letting the analyst confirm or rule out unauthorised logins before containment.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.