200-201 Host-Based Analysis Practice Question
During memory analysis using Volatility, an analyst wants to identify processes with suspicious network connections and potentially injected code. Which THREE plugins should the analyst use? (Select THREE)
⚠ Common exam trap
Watch out — candidates often confuse memory analysis plugins that serve different purposes: hashdump and hivelist are for credential and registry analysis, not for process or network inspection, so candidates might select them if they only associate Volatility with general forensic artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
pstree
Option B, pstree, is correct because it displays the process list as a parent-child tree, which helps the analyst spot anomalous process relationships and suspicious processes that may be tied to injected code or malicious network activity. Option D, malfind, is correct because it scans process memory for signs of code injection such as MZ/PE headers in non-image memory regions with PAGE_EXECUTE_READWRITE permissions, directly addressing the injected-code requirement. Option E, netscan, is correct because it enumerates network artifacts (TCP connections, listening sockets, and UDP endpoints) from memory, allowing identification of processes with suspicious network connections. Option A, hashdump, is not appropriate here because it extracts password hashes from the SAM database rather than analyzing processes or network connections. Option C, hivelist, is not appropriate because it only lists registry hives loaded in memory and does not reveal process, injection, or network details.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
hashdump
Why it's wrong here
hashdump extracts cached password hashes from the SAM database, addressing credential theft rather than the network connections and injected code the analyst must identify. It is tempting because credential dumping is a common memory-forensics goal, and hashdump would be the right plugin when the investigation centres on recovering local account hashes.
- ✓
pstree
Why this is correct
pstree renders the parent-child process hierarchy, exposing anomalous parentage such as a word processor spawning cmd.exe, which hints at injected or masquerading code. Combined with network and injection plugins, it satisfies the requirement to identify suspicious processes during memory analysis.
- ✗
hivelist
Why it's wrong here
hivelist enumerates registry hive locations in memory, supporting registry analysis rather than the process-to-connection mapping and code-injection detection required. It is tempting because registry hives often hold persistence artefacts, and hivelist would be the correct plugin when the task is locating hives for offline registry examination.
- ✓
malfind
Why this is correct
malfind scans process memory for injected code by locating regions marked executable but not backed by a file on disk, such as PE headers in unusual locations. This directly satisfies the requirement to identify potentially injected code, complementing the network-focused plugins needed for suspicious connections.
- ✓
netscan
Why this is correct
Netscan enumerates active and recently closed TCP/UDP endpoints from memory, mapping each socket to its owning process and remote address. This directly satisfies the requirement to identify processes holding suspicious network connections, exposing listening ports and established sessions that may indicate command-and-control or exfiltration activity.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.