200-201 Host-Based Analysis Practice Question
In Windows, prefetch files (C:\Windows\Prefetch\*.pf) are used by the system to speed up application loading. How can an analyst leverage prefetch files during host-based analysis?
⚠ Common exam trap
Cisco often tests the specific purpose of prefetch files versus other forensic artifacts, and the trap here is confusing prefetch files with memory dumps or registry logs, leading candidates to select options that describe unrelated Windows components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They provide evidence of file execution, including frequency and timestamps.
Prefetch files in Windows record metadata about application launches, including the executable path, run count, and last run timestamp. During host-based analysis, an analyst can examine these .pf files to determine which executables have been executed, how often, and when, providing crucial evidence of file execution activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
They provide evidence of file execution, including frequency and timestamps.
Why this is correct
Prefetch files record each executable's name, run count and last-run timestamps, so analysts can confirm that a program executed on the host, how often, and when. This directly satisfies the need to establish file execution evidence during host-based analysis.
- ✗
They store network connection logs.
Why it's wrong here
Prefetch files hold execution metadata, not network connection logs; those reside in artefacts such as Sysmon, firewall logs or NetFlow. It is tempting because both are host-based evidence sources used in incident response, but prefetch answers what ran and when, not which remote addresses a process contacted.
- ✗
They store registry keys modified by the application.
Why it's wrong here
Prefetch files record loaded executables and referenced file paths, not registry modifications; those are captured in registry hives and transaction logs. It is tempting because both are host artefacts examined during triage, but prefetch evidences program execution, whereas registry analysis is required to identify keys an application changed.
- ✗
They contain the contents of the running process memory.
Why it's wrong here
Prefetch files record metadata about loaded executables, such as run counts, timestamps and referenced file paths; they do not capture process memory contents. Memory contents are obtained through memory forensics, which is tempting because both support malware analysis, but prefetch only evidences execution, not in-memory artefacts.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.