easyMultiple Choice
200-201 Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit.
```
{
"event": "Process Creation",
"timestamp": "2024-08-01T10:00:00Z",
"hostname": "DESKTOP-ABC123",
"user": "jsmith",
"process": "C:\\Users\\jsmith\\Downloads\\invoice.exe",
"parent_process": "C:\\Windows\\explorer.exe"
}
```Refer to the exhibit. An EDR alert shows this JSON event. What is the most significant indicator of a potential malware infection?
⚠ Common exam trap
Cisco often tests the distinction between benign system behavior (like explorer.exe as a parent process) and high-risk execution paths (like the Downloads folder), tricking candidates into focusing on the user or event type rather than the contextual risk of the file's origin.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process path is in the Downloads folder.
The process path in the Downloads folder is the most significant indicator because it suggests the executable was downloaded from the internet, a common vector for malware delivery. Attackers frequently use social engineering to trick users into saving malicious files to the Downloads folder, which then execute and initiate infection chains. In EDR analysis, execution from user-writable directories like Downloads is a high-fidelity alert, as legitimate software is rarely launched from this location.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user is 'jsmith'.
Why it's wrong here
A username alone carries no malicious signal; jsmith is simply the account context recorded in the event, and legitimate activity produces identical values. It tempts because attribution feels investigative, yet the account field is the correct focus only when correlating an already-suspicious process to its originating user.
- ✗
The parent process is explorer.exe.
Why it's wrong here
explorer.exe is the normal Windows shell and spawns countless legitimate child processes, so parentage by itself indicates nothing malicious. It tempts because unusual parents such as Office applications spawning scripting engines are strong signals; here the parent is the expected shell, so the anomaly must be sought elsewhere.
- ✓
The process path is in the Downloads folder.
Why this is correct
A process executing from the Downloads folder satisfies the suspicious-location constraint: user-writable directories like Downloads are common malware staging grounds, since standard users can drop and run files there without elevation. This path deviates from expected system or Program Files locations, making it a stronger infection indicator than routine network or registry activity.
- ✗
The event type is 'Process Creation'.
Why it's wrong here
Process Creation is the routine event type that EDR telemetry records for every launched executable, including entirely benign ones, so it cannot distinguish infection. It tempts because process events often carry the malicious command line, but the indicator lies in the process's properties, not the event category itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.