Courseiva

CCNA Cbrops Host Analysis Questions

75 of 118 questions · Page 1/2 · Cbrops Host Analysis topic · Answers revealed

1
MCQhard

A security analyst is examining a Windows 10 host and suspects that an attacker has established persistence using a scheduled task. The analyst runs 'schtasks /query /fo LIST /v' and observes a task named 'WindowsUpdateCheck' with the action 'C:\Users\Public\update.exe' and a trigger set to run every 5 minutes. Which of the following best describes the attacker's technique?

A.The attacker is using a WMI event subscription to maintain persistence and execute a malicious binary at regular intervals.
B.The attacker is using a registry Run key to maintain persistence and execute a malicious binary at regular intervals.
C.The attacker is using a scheduled task to maintain persistence and execute a malicious binary at regular intervals.
D.The attacker is using a service to maintain persistence and execute a malicious binary at regular intervals.
AnswerC

Scheduled tasks are a common persistence mechanism. The task name 'WindowsUpdateCheck' mimics a legitimate update check, but the action points to a binary in C:\Users\Public, which is an unusual location for a legitimate update executable. The frequent trigger (every 5 minutes) ensures the malware runs regularly, maintaining persistence and possibly beaconing to a command-and-control server.

Why this answer

Scheduled tasks are frequently abused by attackers to establish persistence. The task name 'WindowsUpdateCheck' is designed to look benign, but the executable path in C:\Users\Public and the 5-minute interval are suspicious. Attackers use such tasks to ensure their malware runs regularly, even after reboots.

Analysts should investigate the binary and the task's origin.

Exam trap

The trap here is assuming that a task with a legitimate-sounding name is safe, but the executable path and frequency are key indicators of malicious intent.

2
MCQmedium

A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the ASCII string 'MZ' at the beginning. What does this indicate?

A.The file is a plain text file
B.The file is a Windows Portable Executable
C.The file is a Linux ELF binary
D.The file is a PDF document
AnswerB

The ASCII characters 'MZ' (0x4D5A) form the DOS header magic number that every Windows Portable Executable begins with, as defined by the PE format specification. Its presence at offset zero identifies the file as a Windows PE binary rather than a script or document.

Why this answer

The ASCII string 'MZ' at the beginning of a file is the DOS MZ header signature, which identifies the file as a Windows Portable Executable (PE) or a DOS executable. 'MZ' stands for Mark Zbikowski, the Microsoft engineer who designed the format. This signature is the first two bytes of every PE file and is used by Windows loaders to recognize executable images.

Exam trap

200-201 often tests magic-number recognition, and candidates confuse 'MZ' (Windows PE/DOS) with 'ELF' (Linux) or 'PDF' signatures — the key is memorizing the exact byte sequences for each file type.

How to eliminate wrong answers

Option A is wrong because plain text files do not have a mandatory binary signature — they contain readable characters throughout, not a specific 'MZ' magic number. Option C is wrong because Linux ELF binaries begin with the magic bytes 0x7F 0x45 0x4C 0x46 (which spell '\x7fELF'), not 'MZ'. Option D is wrong because PDF documents begin with the signature '%PDF-' (hex 25 50 44 46 2D), not 'MZ'.

3
Multi-Selectmedium

An analyst is examining a Linux system for signs of an attacker establishing persistence. Which TWO of the following locations should the analyst check? (Choose two.)

Select 2 answers
A./etc/passwd
B./proc/self/status
C./etc/systemd/system/
D./etc/crontab
E./home/user/.bash_history
AnswersC, D

Correct. Systemd services can be used for persistence.

Why this answer

Option C, /etc/systemd/system/, is correct because attackers commonly drop malicious .service unit files there to establish persistence via systemd, causing their payload to execute at boot or on a trigger. Option D, /etc/crontab, is correct because scheduled tasks in this file (and related cron directories) are a classic persistence mechanism, allowing an attacker to re-execute code at defined intervals. Option A, /etc/passwd, is not the best choice here since it stores user account information rather than a direct persistence trigger, though it can be abused to add accounts.

Option B, /proc/self/status, is a runtime process status file and does not provide a persistence location. Option E, /home/user/.bash_history, is useful for forensic reconstruction of past commands but is not itself a persistence mechanism.

Exam trap

200-201 often tests persistence locations, and candidates confuse forensic artifacts (like .bash_history) with actual persistence mechanisms — the key is identifying locations that cause automatic code execution across reboots or schedules.

4
MCQhard

An analyst is examining a Windows 10 host and discovers that a service named 'WinDefendSvc' is registered with a binary path of C:\ProgramData\svchost.exe and a display name of 'Windows Defender Service'. The legitimate Windows Defender service uses a different name and binary path. Which conclusion is most accurate?

A.The service is a leftover from a Windows Update that failed to clean up and can be safely ignored, since the binary is named svchost.exe.
B.This is a benign third-party antivirus service that has registered itself under a Microsoft-like name to be trusted by the operating system.
C.This is a legitimate alternate Windows Defender service name used on some Windows 10 builds and should be verified with Get-Service before further action.
D.This indicates a masquerading attempt, because the service name mimics Windows Defender while its binary is placed in a user-writable directory, which is typical of malware persistence.
AnswerD

C:\ProgramData is writable by standard users, unlike system directories, making it a common staging ground for malicious binaries. The service name 'WinDefendSvc' closely mimics the legitimate 'WinDefend' to evade casual inspection. Combined with the non-standard binary path, this is a classic masquerading persistence technique. The analyst should treat it as malicious and investigate the binary and its network behavior.

Why this answer

Legitimate Windows Defender registers as the WinDefend service with its binary under C:\Program Files\Windows Defender. A service named WinDefendSvc pointing to C:\ProgramData\svchost.exe combines two red flags: a typosquatted name impersonating a security product and a binary in a user-writable directory. This pattern is characteristic of masquerading persistence, and the analyst should investigate the binary, its signature, and its network activity rather than dismissing it as legitimate.

Exam trap

The trap here is trusting a service because its name resembles a known Microsoft component, without verifying the actual binary path and digital signature.

5
MCQhard

When analyzing a suspicious PE file, the analyst calculates the file's entropy and finds it to be 7.8. What does a high entropy value typically indicate, and why is it relevant to malware analysis?

A.The file is likely packed or encrypted to evade signature-based detection.
B.The file contains no executable code.
C.The file is likely a legitimate application with high compression.
D.The file's imports are all standard Windows DLLs.
AnswerA

Entropy near 7.8 approaches the theoretical maximum of 8, indicating compressed or encrypted data rather than readable code. Packers and crypters use this to obscure payloads, defeating signature-based detection. This satisfies the stem's requirement to explain what high entropy indicates and its malware-analysis relevance.

Why this answer

A high entropy value (close to 8.0) indicates that the data within the file is highly random, which is a strong sign of packing or encryption. Malware authors use packers to obfuscate the original executable code, making it harder for signature-based detection engines to identify known malicious patterns. In malware analysis, entropy is a quick heuristic to flag files that may be hiding their true content.

Exam trap

Cisco often tests the misconception that high entropy always means the file is malicious, when in fact it only indicates obfuscation or packing—legitimate files can also be packed (e.g., some installers), so entropy must be combined with other indicators like suspicious imports or network signatures.

How to eliminate wrong answers

Option B is wrong because a file with high entropy can still contain executable code that is simply obfuscated; the entropy value does not indicate the absence of code. Option C is wrong because legitimate applications rarely achieve entropy values near 7.8 through compression alone—standard compression algorithms like ZIP or LZMA produce entropy values around 6.5–7.0, not 7.8, and such high entropy is more characteristic of encryption or strong packing. Option D is wrong because the entropy calculation is based on the byte distribution of the entire file, not on the import table; a file with standard Windows DLL imports could still have high entropy if its code section is packed.

6
MCQhard

A security analyst is investigating a Windows host for signs of fileless malware. The analyst runs a memory analysis tool and observes a process named 'powershell.exe' with a parent process of 'winword.exe'. The command line includes '-enc' followed by a long base64 string. Which technique is most likely being used by the attacker?

A.Malicious macro execution
B.Process hollowing
C.DLL injection
D.Scheduled task persistence
AnswerA

The parent process winword.exe spawning powershell.exe with an encoded command is a classic sign of a malicious Microsoft Word macro. Attackers use macros to execute PowerShell commands that download or run payloads, often encoding the command to evade detection. The '-enc' parameter indicates base64-encoded script, a common obfuscation method in macro-based attacks, making this the most likely technique.

Why this answer

The scenario describes winword.exe spawning powershell.exe with an encoded command, a hallmark of malicious macro execution. Attackers embed macros in Word documents that execute PowerShell to download or run payloads, often using base64 encoding to hide the script. Other techniques like DLL injection, process hollowing, or scheduled tasks do not match the observed parent-child relationship and command-line pattern, making macro execution the most likely.

Exam trap

The trap here is assuming that any PowerShell with encoded command is fileless malware, without considering the parent process, which in this case strongly indicates macro execution.

7
MCQeasy

Which Windows artifact stores evidence of file execution, including the path and run count, and is located in C:\Windows\Prefetch?

A.Windows Event Logs
B.Registry hives
C.Scheduled tasks
D.Prefetch files
AnswerD

Prefetch files, stored in C:\Windows\Prefetch with a .pf extension, record executable name, file path, run count and last-run timestamps. This directly satisfies the stem's requirement for an artifact evidencing file execution with path and run count.

Why this answer

Windows Prefetch files, stored in C:\Windows\Prefetch with a .pf extension, record evidence of program execution including the executable path, run count, and timestamps of recent executions. Forensic analysts use them to prove that a binary ran on a system and how many times. This directly matches the artifact described in the question.

Exam trap

200-201 often tests artifact-to-location mapping — candidates confuse Registry execution artifacts (Amcache, ShimCache) with Prefetch, forgetting that Prefetch specifically lives in C:\Windows\Prefetch and stores run counts.

How to eliminate wrong answers

Option A is wrong because Windows Event Logs (e.g., Security 4688, Sysmon 1) record process creation events but do not store run counts or live in C:\Windows\Prefetch. Option B is wrong because Registry hives (e.g., NTUSER.DAT, Amcache, ShimCache) can contain execution evidence but are not located in the Prefetch folder and do not store the same run-count data. Option C is wrong because Scheduled Tasks are persistence/automation artifacts stored in Task Scheduler, not execution-history artifacts in Prefetch.

8
MCQeasy

A Linux administrator checks authentication logs to investigate a possible brute-force attack. Which log file typically contains records of successful and failed SSH login attempts?

A./var/log/kern.log
B./var/log/auth.log
C./var/log/messages
D./var/log/syslog
AnswerB

/var/log/auth.log records PAM authentication events on Debian-based Linux systems, capturing both successful and failed SSH login attempts with source addresses and usernames. This directly satisfies the stem's requirement to investigate brute-force activity, since repeated failures from one origin become visible there.

Why this answer

On Debian/Ubuntu Linux systems, /var/log/auth.log records authentication-related events including successful and failed SSH logins, sudo usage, and PAM activity. It is the primary log file for investigating brute-force attacks against SSH. This matches the question's requirement.

Exam trap

200-201 often tests Linux log file locations across distributions — candidates pick /var/log/messages or /var/log/syslog assuming they contain auth events, forgetting that Debian/Ubuntu isolate authentication in /var/log/auth.log.

How to eliminate wrong answers

Option A is wrong because /var/log/kern.log records kernel messages (hardware, drivers, kernel panics), not authentication events. Option C is wrong because /var/log/messages is a general system log on some distributions (RHEL/CentOS) but does not specifically capture SSH authentication on Debian-based systems — auth events go to auth.log or secure. Option D is wrong because /var/log/syslog is a general system log aggregating many services; while it may contain some auth entries on certain configurations, auth.log is the canonical, dedicated file for authentication records.

9
MCQmedium

An analyst uses Volatility on a memory dump and runs the 'pstree' command. What specific information does this provide compared to 'pslist'?

A.It shows only hidden processes.
B.It extracts command line arguments.
C.It displays the process tree hierarchy.
D.It lists loaded kernel modules.
AnswerC

The pstree plugin reconstructs parent-child relationships by following inherited process identifiers, revealing the ancestry and nesting that pslist's flat enumeration omits. This satisfies the stem's comparison requirement, exposing processes whose parent has exited and been reparented, which a simple listing cannot show.

Why this answer

The Volatility 'pstree' plugin displays the process tree hierarchy, showing parent-child relationships between processes. Unlike 'pslist', which lists processes in a flat table ordered by creation time, 'pstree' visually indents child processes under their parents. This helps analysts identify suspicious process lineage, such as a web server spawning a shell.

Exam trap

200-201 often tests the specific output of Volatility plugins, and candidates confuse 'pstree' (hierarchy) with 'pslist' (flat list) or 'psscan' (hidden process detection) — the key is remembering that 'pstree' adds parent-child visualization.

How to eliminate wrong answers

Option A is wrong because 'pstree' does not specifically show hidden processes — that is the domain of 'psscan' (which scans for pool-tagged process objects) or 'psxview' (which cross-references multiple sources to find hidden processes). Option B is wrong because command-line arguments are extracted by the 'cmdline' plugin, not 'pstree'. Option D is wrong because loaded kernel modules are listed by the 'modules' plugin, not 'pstree'.

10
MCQeasy

When performing file analysis, which method is most reliable for determining the actual file type regardless of its extension?

A.Opening the file in a text editor
B.Checking the file extension
C.Examining the file's magic bytes
D.Checking the file size
AnswerC

Magic bytes are fixed signature values at the start of a file's binary content, so they identify the true format independently of the filename extension. An attacker can rename a malicious executable to .txt, but the magic bytes still reveal the actual type, satisfying the requirement to determine file type regardless of extension.

Why this answer

Magic bytes (or file signatures) are unique byte sequences at the beginning of a file that identify its format regardless of the file extension. This method is reliable because it examines the actual binary content, such as the 'PK' header for ZIP files or '‰PNG' for PNG images, rather than relying on user-assigned metadata that can be easily changed.

Exam trap

Cisco often tests the concept that file extensions are user-modifiable metadata and thus unreliable, while magic bytes provide a content-based verification that is independent of the filename.

How to eliminate wrong answers

Option A is wrong because opening a file in a text editor only displays raw text or garbled characters for binary files, and it does not reliably identify the file type; it may also misinterpret encoding or execute harmful content. Option B is wrong because checking the file extension is unreliable—extensions can be renamed arbitrarily (e.g., renaming a .exe to .jpg) and do not reflect the actual file content. Option D is wrong because checking the file size provides no information about the file's structure or format; two files of identical size can be completely different types.

11
MCQhard

A security analyst is investigating a Linux server that was compromised. The attacker used a rootkit to hide processes and files. The analyst runs 'lsmod' and notices a kernel module named 'hideproc' that is not recognized. Which command should the analyst use to determine the module's file path and potentially identify the rootkit?

A.lsmod | grep hideproc
B.dmesg | grep hideproc
C.rmmod hideproc
D.modinfo hideproc
AnswerD

modinfo displays information about a kernel module, including its filename, description, author, and license. Running 'modinfo hideproc' will show the full path to the module file, which can then be analyzed or removed. This directly helps identify the rootkit's location.

Why this answer

The analyst needs to find the file path of the suspicious kernel module to analyze or remove it. The modinfo command provides detailed information about a module, including its filename and location. This is the correct tool for identifying where the rootkit module resides on disk, enabling further forensic analysis or cleanup.

Exam trap

The trap here is confusing listing loaded modules with obtaining detailed module information, such as the file path, which requires modinfo.

12
Multi-Selectmedium

During memory analysis using Volatility, an analyst wants to identify processes with suspicious network connections and potentially injected code. Which THREE plugins should the analyst use? (Select THREE)

Select 3 answers
A.hashdump
B.pstree
C.hivelist
D.malfind
E.netscan
AnswersB, D, E

pstree renders the parent-child process hierarchy, exposing anomalous parentage such as a word processor spawning cmd.exe, which hints at injected or masquerading code. Combined with network and injection plugins, it satisfies the requirement to identify suspicious processes during memory analysis.

Why this answer

Option B, pstree, is correct because it displays the process list as a parent-child tree, which helps the analyst spot anomalous process relationships and suspicious processes that may be tied to injected code or malicious network activity. Option D, malfind, is correct because it scans process memory for signs of code injection such as MZ/PE headers in non-image memory regions with PAGE_EXECUTE_READWRITE permissions, directly addressing the injected-code requirement. Option E, netscan, is correct because it enumerates network artifacts (TCP connections, listening sockets, and UDP endpoints) from memory, allowing identification of processes with suspicious network connections.

Option A, hashdump, is not appropriate here because it extracts password hashes from the SAM database rather than analyzing processes or network connections. Option C, hivelist, is not appropriate because it only lists registry hives loaded in memory and does not reveal process, injection, or network details.

Exam trap

The trap here is confusing memory analysis plugins that serve different purposes: hashdump and hivelist are for credential and registry analysis, not for process or network inspection, so candidates might select them if they only associate Volatility with general forensic artifacts.

13
MCQmedium

An analyst is examining a suspicious file that appears to be a PDF but when checking the magic bytes at offset 0, sees '50 4B 03 04'. What does this indicate?

A.The file is a genuine PDF file
B.The file is a plain text file
C.The file is a ZIP archive
D.The file is an executable
AnswerC

The magic bytes 50 4B 03 04 are the ZIP local file header signature ('PK\x03\x04'). Despite the .pdf extension, the file's actual container format is ZIP, which is typical of Office documents and JAR archives and indicates the extension has been spoofed.

Why this answer

The magic bytes '50 4B 03 04' at offset 0 are the ZIP file signature (PK\x03\x04). A genuine PDF must begin with '%PDF' (hex 25 50 44 46). Since the file claims to be a PDF but its header identifies it as a ZIP archive, this is a classic file-extension spoofing or polyglot technique used by malware to evade detection.

Exam trap

200-201 often tests whether candidates trust file extensions over actual file signatures — the trap is assuming a .pdf extension means the file is a PDF, when magic bytes reveal the true type.

How to eliminate wrong answers

Option A is wrong because a real PDF starts with the ASCII bytes '%PDF' (25 50 44 46), not 50 4B 03 04. Option B is wrong because plain text files have no fixed magic number and would not begin with the ZIP signature. Option D is wrong because Windows executables begin with 'MZ' (4D 5A), and ELF binaries begin with 7F 45 4C 46 — neither matches 50 4B 03 04.

14
MCQhard

A security analyst is examining a Linux server that is suspected of being compromised. The analyst runs `ls -l /proc/<PID>/exe` for a suspicious process and sees that the symbolic link points to `/tmp/.hidden/update` but the file no longer exists on disk. Which conclusion is most accurate?

A.The process is a kernel thread and does not have an executable on disk.
B.The process is running from a memory-mapped file and has no on-disk executable.
C.The process is a zombie and has already terminated.
D.The executable file was deleted while the process is still running.
AnswerD

On Linux, when an executable is deleted while a process is running, the /proc/<PID>/exe symlink still exists but points to the original path with a ' (deleted)' suffix, and the file is no longer visible on disk. This is a common malware technique to hide the binary while keeping it running. The analyst can recover the binary from /proc/<PID>/exe before the process exits.

Why this answer

On Linux, the /proc/<PID>/exe symlink points to the executable file. If that file is deleted while the process is running, the symlink remains but the target path is marked as deleted, and the file is no longer accessible via the filesystem. This is a known malware tactic to hinder forensic analysis.

The analyst should copy /proc/<PID>/exe to preserve the binary before the process terminates.

Exam trap

The trap here is interpreting a broken /proc/<PID>/exe symlink as evidence that the process is a zombie or kernel thread, when it actually indicates a deleted executable still running from memory.

15
MCQeasy

A security analyst is investigating a Windows host suspected of malware infection. Which tool would allow the analyst to view parent-child relationships of running processes and inspect command line arguments?

A.Process Explorer
B.Task Manager
C.tasklist command
D.Resource Monitor
AnswerA

Process Explorer displays a live process tree, exposing parent-child relationships that reveal suspicious spawning, such as Office launching PowerShell. Its command-line column shows the exact arguments passed to each process, satisfying the investigation's requirement to inspect execution details on the suspect Windows host.

Why this answer

Process Explorer, part of Microsoft Sysinternals, provides a hierarchical view of running processes, showing parent-child relationships and allowing inspection of command-line arguments via the process properties. It also offers advanced features like VirusTotal integration and handle/ DLL views, making it the ideal tool for this investigation.

Exam trap

The trap is confusing basic process listing tools (Task Manager, tasklist) with advanced forensic tools; candidates must remember that only Process Explorer (and similar tools like Process Hacker) shows both parent-child relationships and command-line arguments natively.

How to eliminate wrong answers

Option B is wrong because Task Manager shows a flat list of processes and does not display parent-child relationships or full command-line arguments by default. Option C is wrong because the tasklist command lists processes but does not show parent PIDs or command-line arguments (unless used with /v, which still lacks parent info). Option D is wrong because Resource Monitor focuses on resource utilization (CPU, disk, network) and does not provide process lineage or command-line details.

16
MCQmedium

An analyst is examining a Linux server and notices an unusual systemd service that starts automatically. Which command would be used to disable this service?

A.systemctl disable servicename
B.systemctl stop servicename
C.systemctl remove servicename
D.systemctl mask servicename
AnswerA

systemctl disable removes the service's symlinks from the systemd unit configuration, preventing it from starting automatically at boot while leaving the unit file intact. This directly addresses the autostart constraint, unlike stop, which only halts the running instance.

Why this answer

The 'systemctl disable' command prevents a service from starting automatically at boot.

17
MCQeasy

A security analyst is reviewing a Windows system for signs of malware persistence. The analyst notices a suspicious executable named 'updater.exe' in the Startup folder. Which Windows feature is being abused by the malware in this scenario?

A.Registry Run Keys
B.Windows Services
C.Task Scheduler
D.Startup Folder
AnswerD

The Startup folder is a directory that contains shortcuts or executables that run automatically when a user logs in. Malware often places a copy of itself or a shortcut in this folder to achieve persistence. The scenario describes an executable named 'updater.exe' in the Startup folder, which is a classic persistence technique. Thus, the Startup folder is the correct answer.

Why this answer

The Startup folder is a well-known location that Windows uses to automatically launch programs when a user logs in. Malware frequently places a copy of itself or a shortcut in this folder to ensure it runs every time the user logs in. The presence of 'updater.exe' in the Startup folder indicates that this persistence mechanism is being abused.

Other methods like Services, Task Scheduler, or Registry Run keys are also used by malware but are not described in this scenario.

Exam trap

The trap here is confusing the Startup folder with other persistence mechanisms like Registry Run keys, which are often used but are not the same as placing a file in the Startup folder.

18
MCQhard

A Linux host has an unusual cron job that runs a script from /tmp every minute. The analyst checks /etc/crontab and /var/spool/cron/ but finds nothing. Where else could the cron job be defined?

A./etc/cron.d/
B./etc/cron.hourly/
C./etc/cron.allow
D.~/.bashrc
AnswerA

This directory contains per-package cron definitions.

Why this answer

The cron job is defined in /etc/cron.d/ because this directory allows system administrators to drop individual cron configuration files that are parsed by the cron daemon. Unlike /etc/crontab and /var/spool/cron/ (which contain user-specific crontabs), /etc/cron.d/ is a standard location for package-maintained or custom cron jobs that run with system privileges. The fact that the analyst found nothing in the other two locations strongly suggests the job is defined in /etc/cron.d/.

Exam trap

Cisco often tests the distinction between cron configuration directories and control files, trapping candidates who confuse /etc/cron.allow (an access control list) with a location where cron jobs are actually defined.

How to eliminate wrong answers

Option B is wrong because /etc/cron.hourly/ is a directory for scripts that run on an hourly schedule, not for defining arbitrary cron jobs with specific minute-level intervals; it uses run-parts and does not support custom cron syntax like 'every minute'. Option C is wrong because /etc/cron.allow is a control file that lists users allowed to use cron, not a location where cron jobs are defined. Option D is wrong because ~/.bashrc is a shell initialization script executed for interactive login shells, not a cron configuration file; cron jobs cannot be defined there.

19
MCQhard

A security analyst is examining a Linux system for signs of a rootkit. The analyst runs `lsmod` and notices a kernel module named `hideproc` that is not recognized. The analyst then runs `rmmod hideproc` but receives an error that the module is in use. Which of the following is the MOST likely reason the module cannot be removed?

A.The module's reference count is artificially incremented to prevent removal.
B.The module was loaded with `modprobe` and requires `modprobe -r` to remove.
C.The module is compiled into the kernel and cannot be removed.
D.The module is currently being used by a legitimate process such as `systemd`.
AnswerA

Rootkits often manipulate the module's reference count (refcount) to prevent removal. They may increment it or hook the `delete_module` syscall to return an error. This makes the module appear 'in use' even when no legitimate process uses it. Thus, the rootkit maintains persistence by blocking `rmmod`. This is a common rootkit technique.

Why this answer

Rootkits frequently manipulate kernel structures to prevent their removal. By incrementing the module's reference count or hooking the `delete_module` system call, they make `rmmod` fail with 'in use'. This ensures the rootkit remains loaded.

Analysts should use memory forensics or reboot to a trusted environment to remove such modules.

Exam trap

The trap here is assuming that 'in use' always means a legitimate process is using the module, when a rootkit can fake the reference count to block removal.

20
MCQmedium

An analyst is investigating a Windows system for potential malware persistence. The analyst discovers a scheduled task that runs a PowerShell script every hour. The script downloads and executes a payload from a remote server. Which of the following Windows artifacts would BEST provide the original creation time and the author of this scheduled task?

A.C:\Windows\Tasks\<TaskName>
B.C:\Windows\System32\Tasks\<TaskName>
C.C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx
D.C:\Windows\Prefetch\<TaskName>.pf
AnswerB

This file stores the XML definition of the scheduled task, including its creation time, author, and actions. It is the authoritative source for the task's configuration and metadata. Analyzing this file can reveal when and by whom the task was created, which is crucial for determining if it is malicious.

Why this answer

The scheduled task definition file in C:\Windows\System32\Tasks\ contains an XML representation that includes metadata such as the task's creation time and author. This is the most direct artifact for determining the origin of a suspicious scheduled task, as it is written when the task is created.

Exam trap

The trap here is confusing the task scheduler operational log with the task definition file; the log records execution events, not creation metadata.

21
MCQmedium

An analyst finds a registry modification under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options'. What is the primary use of this registry key?

A.To configure network firewall rules for the image
B.To set a debugger that runs when the image is executed
C.To change the file extension association for the image
D.To log all execution of the image to the Event Log
AnswerB

Image File Execution Options supports a Debugger value that Windows launches instead of the named executable. Attackers abuse this for persistence by pointing the debugger at malicious code, so the key's legitimate purpose is specifying a debugger for the image.

Why this answer

The Image File Execution Options (IFEO) registry key is used to specify a debugger that launches when a particular executable is started. Attackers abuse this by setting a 'Debugger' value to a malicious binary, achieving persistence and execution hijacking. Legitimate use includes attaching debuggers to specific processes, but the primary security-relevant function is debugger redirection.

Exam trap

The trap is assuming IFEO is a benign debugging-only feature; candidates forget that its debugger redirection is a well-known persistence mechanism, so they overlook the malicious potential and pick a logging or firewall answer.

How to eliminate wrong answers

Option A is wrong because firewall rules for images are configured through Windows Firewall policies, not through IFEO, which is strictly about process execution behavior. Option C is wrong because file extension associations are stored under HKEY_CLASSES_ROOT and user shell settings, not under IFEO. Option D is wrong because IFEO does not log execution to the Event Log; it only redirects execution to a debugger, and any logging would be a side effect of the debugger itself, not a built-in feature.

22
Multi-Selecthard

An analyst is using Volatility to analyze a memory dump. Which TWO plugins are most effective for detecting code injection?

Select 2 answers
A.ldrmodules
B.pslist
C.malfind
D.pstree
E.netscan
AnswersA, C

ldrmodules enumerates loaded modules via three linked lists (InLoad, InInit, InMem) and flags discrepancies, exposing injected DLLs unlinked from the loader's lists. This directly satisfies the scenario's requirement to detect code injection in the memory dump.

Why this answer

Option A, ldrmodules, is correct because it compares the three DLL/module lists maintained in the PEB (InLoad, InInit, InMem) and flags modules that appear in memory but are absent from the loader list, a classic sign of injected or unlinked DLLs. Option C, malfind, is correct because it scans process memory for pages with MZ/PE headers that are not backed by a file on disk and have suspicious protection flags such as PAGE_EXECUTE_READWRITE, which is the standard indicator of injected code. The unmarked options do not belong: pslist merely walks the doubly linked process list to enumerate running processes, pstree shows parent-child process relationships, and netscan lists network connections and sockets; none of these inspect module lists or memory pages for injected code.

Exam trap

200-201 often tests the specific Volatility plugins for different forensic tasks; candidates may confuse pslist/pstree (process listing) with malfind/ldrmodules (injection detection).

23
MCQmedium

A security analyst is reviewing Windows Event Logs on a domain controller. The analyst sees multiple Event ID 4769 (Kerberos service ticket was requested) with the same user account but different service names, occurring in a short time frame. Which of the following attacks is MOST likely indicated?

A.Kerberoasting
B.Golden Ticket
C.Pass-the-Hash
D.DCSync
AnswerA

Kerberoasting involves requesting Kerberos service tickets (TGS) for service accounts and cracking them offline. Event ID 4769 is logged when a TGS is requested. Multiple requests for different services in a short time by the same user is a classic sign. The attacker then extracts the ticket and attempts to crack the service account's password.

Why this answer

Kerberoasting is an attack where an adversary requests Kerberos service tickets for service accounts and then cracks them offline. Event ID 4769 is generated for each TGS request. A burst of 4769 events with different service names from the same user is a strong indicator.

Monitoring for such patterns helps detect Kerberoasting attempts.

Exam trap

The trap here is confusing Kerberoasting with other Kerberos attacks; 4769 specifically logs service ticket requests, which are central to Kerberoasting, not Golden Ticket or DCSync.

24
Multi-Selectmedium

An analyst is investigating a Windows system for signs of malware persistence. Which TWO registry locations are commonly used by malware to achieve automatic startup? (Choose two.)

Select 2 answers
A.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
B.HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
C.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
D.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
E.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\AppInit_DLLs
AnswersA, D

User-specific Run key.

Why this answer

A is correct because the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run registry key is a standard autostart location that launches programs when the current user logs in. Malware frequently writes a value here to achieve persistence without requiring administrative privileges, as it affects only the current user's session.

Exam trap

Cisco often tests the distinction between Run and RunOnce keys, and the trap here is that candidates mistakenly choose RunOnce options (B or C) thinking they provide persistence, when in fact they only execute a program a single time and then remove the entry.

25
MCQhard

An analyst is examining a Windows system for evidence of credential dumping. The analyst runs 'Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4688}' and filters for processes with 'lsass.exe' as the target. The output shows that a process named 'procdump.exe' was executed with the command line 'procdump.exe -ma lsass.exe lsass.dmp'. Which type of attack does this indicate?

A.A backup process capturing system state
B.Credential dumping via LSASS memory dump
C.A malware family using process injection into LSASS
D.A legitimate troubleshooting step to diagnose LSASS crashes
AnswerB

Procdump is a legitimate Sysinternals tool, but when used to dump the memory of lsass.exe, it is a common technique for credential dumping. The -ma flag captures a full memory dump, which can then be parsed with tools like Mimikatz to extract plaintext passwords or hashes. This is a clear indicator of credential theft.

Why this answer

Using procdump to dump LSASS memory is a well-known credential dumping technique. Attackers often rename procdump or use it directly to avoid detection. The resulting dump file can be exfiltrated and analyzed offline to extract credentials.

Detecting this behavior involves monitoring for process creation of procdump.exe with lsass.exe as an argument, as well as other tools like Task Manager or comsvcs.dll.

Exam trap

The trap here is dismissing procdump as a legitimate tool and missing its malicious use for credential dumping, especially when targeting LSASS.

26
MCQmedium

A Windows event log review shows Event ID 4625 multiple times from a single source IP. What does this event indicate, and which log contains it?

A.Successful logon; System log
B.Service start; System log
C.Failed logon; Security log
D.Account creation; Application log
AnswerC

Event ID 4625 is logged whenever a logon attempt fails, recording the account and source. Repeated occurrences from one source IP suggest brute-force or password-guessing activity, and Windows writes this event to the Security log.

Why this answer

Event ID 4625 is a failed logon attempt, recorded in the Security log.

27
MCQmedium

A Windows Event Log shows Event ID 4625 multiple times from the same source IP address. What type of activity does this indicate?

A.Failed logon attempts indicating a possible brute-force attack
B.Successful logon after multiple attempts
C.Credential validation by a domain controller
D.A user account was created
AnswerA

Event ID 4625 is logged whenever a logon attempt fails, and repeated occurrences from one source IP address indicate sustained authentication failures consistent with brute-force activity. This directly satisfies the stem's constraint of multiple 4625 events from the same source, distinguishing it from successful logons (4624) or lockouts (4740).

Why this answer

Event ID 4625 indicates a failed logon attempt. Multiple failures from the same source suggest a brute-force attack.

28
MCQhard

A threat hunter is examining a Windows 10 host and wants to determine whether a suspicious executable was recently run by a user. The hunter knows that Windows records application execution history in the registry under the UserAssist key. Which location should the hunter inspect to find this data for the currently logged-on user?

A.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
B.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
C.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count
D.HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings
AnswerC

The UserAssist key under HKCU stores ROT13-encoded entries for programs launched through Windows Explorer, including the executable name and a run counter. Inspecting the Count subkey under the GUID path reveals execution history for the current user, which is exactly what the threat hunter needs to confirm recent execution.

Why this answer

UserAssist under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist stores per-user execution history for programs launched through Explorer. The Count subkey under each GUID contains ROT13-encoded values that include the program path and a run counter, letting the hunter confirm recent execution by the current user.

Exam trap

The trap here is confusing execution-history artifacts like UserAssist with autostart persistence keys like Run, which record configuration rather than a history of what actually ran.

29
MCQmedium

During incident response on a Linux server, an analyst runs 'ss -tlnp' and sees an SSH service listening on a non-standard high port. Which step should the analyst take next to investigate potential unauthorized access?

A.Review the bash history of root user.
B.Check /etc/crontab for malicious scheduled tasks.
C.Run 'ps aux' to list all processes.
D.Examine /var/log/auth.log for successful logins.
AnswerD

A non-standard SSH port suggests possible backdoor or compromised service, so the analyst must determine whether anyone authenticated successfully. /var/log/auth.log records SSH authentication events, letting the analyst confirm or rule out unauthorised logins before containment.

Why this answer

The correct next step is to examine /var/log/auth.log because it records authentication events, including successful SSH logins. Since the SSH service is listening on a non-standard high port, an attacker may have modified the SSH configuration to evade detection and then logged in. Reviewing auth.log will reveal if any unauthorized successful logins occurred, along with source IPs, usernames, and timestamps, which are critical for determining the scope of the incident.

This directly addresses the potential unauthorized access indicated by the unusual listening port.

Exam trap

The trap here is that candidates may focus on persistence mechanisms (like cron jobs) or process listing instead of the immediate authentication evidence, confusing the step of verifying unauthorized access with later stages of incident response.

How to eliminate wrong answers

Option A is wrong because reviewing root's bash history may show commands executed after login, but it does not confirm whether an unauthorized login occurred or provide authentication details; it is a post-compromise artifact, not the immediate next step to investigate access. Option B is wrong because checking /etc/crontab for malicious scheduled tasks is a persistence mechanism check, not directly related to investigating the SSH service on a non-standard port; it assumes the attacker already established persistence and skips verifying initial access. Option C is wrong because running 'ps aux' lists current processes, which might show the SSH daemon but does not provide historical authentication data or confirm unauthorized access; it is useful for live analysis but less specific than auth.log for login events.

30
MCQhard

A security analyst is investigating a Linux server that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees the output: '/proc/1234/exe -> /tmp/.hidden/backdoor (deleted)'. What does this output indicate?

A.The process 1234 is a legitimate system process that was updated, and the old executable was deleted.
B.The process 1234 is a zombie process that has terminated but still appears in the process list.
C.The process 1234 is running from a deleted executable file, which may indicate malware hiding its presence.
D.The process 1234 has a corrupted executable file that needs to be replaced.
AnswerC

The output shows that the executable for process 1234 was deleted from the filesystem but is still running. This is a common technique used by malware to hide its executable, making it difficult to find on disk. The path '/tmp/.hidden/backdoor' suggests a suspicious location. Thus, this indicates potential malware activity.

Why this answer

The output indicates that process 1234 is executing from a file that has been deleted from the filesystem. Malware often deletes its executable after launching to evade detection by file-based scans. The hidden directory and suspicious name 'backdoor' further suggest malicious intent.

Therefore, the correct interpretation is that the process is running from a deleted executable, a common malware hiding technique.

Exam trap

The trap here is assuming that a deleted executable always indicates a benign update, ignoring the suspicious path and the stealth tactic used by malware.

31
MCQhard

During forensic analysis of a Windows host, an analyst finds a file in C:\Windows\Prefetch with the name 'MALWARE.EXE-3F2A1B0C.pf'. Which type of information can be extracted from this prefetch file to assist the investigation?

A.The number of times the executable has been run and the last execution timestamp
B.The file's SHA256 hash and digital signature status
C.The registry keys modified by the executable during execution
D.The command-line arguments used when the executable was launched
AnswerA

Prefetch files record run count and last-write execution timestamps for each executable, letting the analyst establish when MALWARE.EXE last ran and how frequently. This supports timeline reconstruction, though it does not reveal command-line arguments or network connections.

Why this answer

Windows Prefetch files (.pf) store execution metadata for applications, including the run count and the last time the executable was executed (plus up to the last eight run timestamps on some Windows versions). This makes them a primary artifact for establishing whether and when malware ran on a host.

Exam trap

The trap is assuming prefetch captures command-line arguments or registry changes — it does not; those come from process-creation auditing and registry artifacts respectively, and candidates often conflate forensic artifacts.

How to eliminate wrong answers

Option B is wrong because prefetch files do not store cryptographic hashes or digital signature status — those are obtained via tools like Get-FileHash or sigcheck against the executable itself. Option C is wrong because registry modifications are tracked by artifacts such as registry transaction logs, RegRipper output, or Sysmon Event ID 13, not by prefetch. Option D is wrong because command-line arguments are captured by process creation auditing (Event ID 4688 with command-line logging) or Sysmon Event ID 1, not by prefetch.

32
Multi-Selectmedium

A security analyst is triaging a Windows server that may have been compromised. The analyst needs to identify which network connections are currently established by processes on the host and which executable is responsible for each connection. Which two native tools provide this information? (Choose two.)

Select 2 answers
A.ipconfig /all
B.arp -a
C.Get-NetTCPConnection -State Established
D.route print
E.netstat -ano
AnswersC, E

Get-NetTCPConnection is a PowerShell cmdlet that returns TCP connection objects, and its OwningProcess property gives the PID responsible for each connection. Filtering on the Established state focuses the output on active sessions and makes it straightforward to correlate them with process information.

Why this answer

Mapping active connections to the processes that own them requires tools that expose both socket state and the owning PID. netstat with the -a, -n, and -o switches reports all connections numerically with the PID, while the Get-NetTCPConnection cmdlet returns objects whose OwningProcess property carries the same identifier. Either output can then be joined with a process listing to name the responsible executable.

Exam trap

The trap here is reaching for configuration tools such as ipconfig or route print, which describe the host's network setup rather than its live connections and owning processes.

33
MCQeasy

An analyst is investigating a Windows system for signs of malware persistence. Which registry key is commonly used by malware to run automatically at user logon?

A.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
B.HKLM\SYSTEM\CurrentControlSet\Services
C.HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
AnswerA

HKCU\Software\Microsoft\Windows\CurrentVersion\Run loads programs automatically at user logon, satisfying the persistence requirement. Because it resides in the per-user hive, malware needs no administrative rights to write there, making it a favoured autostart location. HKLM's equivalent requires elevation, so HKCU is the common low-privilege choice.

Why this answer

HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a per-user registry key that specifies programs to run automatically when the user logs on. Malware commonly uses this key for persistence because it executes in the user's context without requiring administrative privileges. This makes it a primary target for autostart persistence.

Exam trap

200-201 often tests the distinction between persistence keys (Run, RunOnce) and forensic artifacts (UserAssist, Services) — candidates may pick UserAssist because it sounds like it tracks user activity, but it does not provide autostart persistence.

How to eliminate wrong answers

Option B is wrong because HKLM\SYSTEM\CurrentControlSet\Services is used for Windows services, which run at system startup — while malware can abuse services, the question specifically asks for user logon persistence, and this key requires admin rights to modify. Option C is wrong because HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall stores uninstall information for installed programs, not autostart entries. Option D is wrong because HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist tracks program execution counts and GUI usage, not autostart persistence — it is forensic evidence of execution, not a persistence mechanism.

34
MCQhard

An analyst is analyzing a suspicious PE file. The file's entropy is high (close to 8.0), and the section names appear random. What does this likely indicate?

A.The file is likely packed or encrypted.
B.The file is a script compiled to an executable.
C.The file is a legitimate Windows system file.
D.The file has been digitally signed.
AnswerA

Entropy near 8.0 indicates near-random byte distribution, and randomised section names are typical of packers. Legitimate compiled code shows lower entropy with recognisable section names like .text, so packing or encryption is the likely explanation.

Why this answer

High entropy close to 8.0 indicates that the data is highly random, which is characteristic of packed or encrypted content. Malware authors use packers and crypters to compress and encrypt the executable, making static analysis difficult. Random section names further suggest that the PE file has been modified by a packer, as legitimate compilers typically produce meaningful section names like .text and .data.

Exam trap

200-201 often tests the association between high entropy and packing/encryption. Candidates may confuse entropy with digital signatures or compilation artifacts. The key is to remember that entropy measures randomness, and packed/encrypted files exhibit high randomness.

How to eliminate wrong answers

Option B is wrong because a script compiled to an executable would typically have normal entropy and standard section names, not random ones. Option C is wrong because legitimate Windows system files are usually not packed and have standard section names and lower entropy. Option D is wrong because digital signatures do not affect entropy or section names; signed files can still be packed, but the presence of a signature is unrelated to high entropy.

35
MCQmedium

A security analyst is examining a Linux system for signs of a compromised user account. The analyst runs `grep ':0:0:' /etc/passwd` and finds an entry for user `backup` with UID 0. The legitimate backup user should have a UID of 1001. Which of the following is the MOST likely explanation?

A.The output is a false positive because `grep ':0:0:'` also matches group ID 0, not just UID.
B.The backup user was accidentally assigned UID 0 during system installation.
C.An attacker modified /etc/passwd to give the backup user root privileges for persistence or privilege escalation.
D.The backup user is a system account that is supposed to have UID 0 for performing backup operations.
AnswerC

Changing a user's UID to 0 in /etc/passwd grants that account full root privileges. Attackers often do this to create a backdoor root account that blends in with legitimate users. The discrepancy between the expected UID (1001) and the actual UID (0) is a strong indicator of malicious modification and should be investigated immediately.

Why this answer

In /etc/passwd, the third field is the UID. UID 0 is reserved for the root account. If a non-root user like backup has UID 0, it means that account has root privileges.

This is a common attacker technique to maintain access: they either modify an existing account or create a new one with UID 0. The analyst should investigate the file's modification time, check for other anomalies, and review authentication logs for the backup user.

Exam trap

The trap here is assuming that a UID of 0 for a non-root user is a benign misconfiguration rather than a deliberate malicious change.

36
Multi-Selecteasy

A Windows analyst uses Process Explorer to investigate parent-child relationships. Which TWO characteristics are commonly associated with malicious processes?

Select 2 answers
A.A parent process with a valid digital signature
B.A process running from a user's Temp folder with a random name
C.A process with a long uptime and low CPU usage
D.A process chain where the parent is svchost.exe and child is explorer.exe
E.A child process spawned by a document reader (e.g., winword.exe spawning cmd.exe)
AnswersB, E

Processes executing from a user's Temp directory with randomised filenames evade signature-based detection and are atypical of legitimate software, which installs to Program Files or AppData. This masquerading behaviour satisfies the stem's request for a malicious parent-child indicator.

Why this answer

Option B is correct because malware frequently drops and executes its payload from user-writable directories such as %TEMP% (e.g., C:\Users\<user>\AppData\Local\Temp) using randomized file names to evade signature-based detection and blend into transient files. Option E is correct because a document reader like winword.exe spawning a command interpreter such as cmd.exe (or powershell.exe) is a classic indicator of a malicious macro or exploit performing code execution, since legitimate Word usage does not normally launch shells. Option A is not suspicious by itself, as validly signed parent processes are typical of legitimate software and signatures indicate trustworthiness rather than malice.

Option C describes benign behavior, since long uptime with low CPU is normal for many background services. Option D is also not inherently malicious, because svchost.exe spawning explorer.exe can occur in legitimate scenarios and is not a standard malware parent-child pattern.

Exam trap

200-201 often tests the ability to distinguish benign from malicious process characteristics. Candidates may be misled by options that sound suspicious but are actually normal (e.g., signed parent process) or by unusual but not definitively malicious chains (svchost.exe to explorer.exe). The key is to focus on well-known malicious indicators like Temp folder execution and document readers spawning shells.

37
MCQhard

A CyberOps analyst is examining a Windows workstation and finds that a scheduled task named 'MicrosoftEdgeUpdateTask' exists in Task Scheduler, but the Task Scheduler GUI shows it as disabled. The analyst suspects it was created by malware to masquerade as a legitimate updater. Which artifact should the analyst check to determine the exact executable path and arguments the task would run if it were enabled?

A.The XML definition of the task, stored under C:\Windows\System32\Tasks and readable with schtasks /query /xml.
B.The prefetch file for schtasks.exe located in C:\Windows\Prefetch.
C.The Task Scheduler operational event log (Microsoft-Windows-TaskScheduler/Operational) filtered for Event ID 106.
D.The file system journal for the C: volume, queried with fsutil usn readjournal, filtered to the Tasks directory.
AnswerA

Each scheduled task has an XML definition stored in the Tasks folder that contains the complete action list, including the executable path, arguments, working directory, triggers, and principal. Reading it with schtasks /query /xml reveals exactly what the task would run when enabled, regardless of the GUI's disabled indicator, making it the correct artifact to inspect.

Why this answer

The authoritative source for what a scheduled task executes is its XML definition, which lists the action's executable, arguments, and working directory. Reading it directly with schtasks /query /xml bypasses the GUI's disabled display and reveals the true payload. Event logs and file system journals provide timing and creation context but not the task's action content, so they cannot answer what the task would run.

Exam trap

The trap here is trusting the disabled state shown in the Task Scheduler GUI, when the underlying XML definition still contains the full malicious action and can be re-enabled at any time.

38
MCQmedium

An analyst is reviewing Windows Security Event Logs and finds Event ID 4648. What does this event indicate?

A.A logon attempt using explicit credentials was attempted.
B.A service was installed.
C.A user account was created.
D.A scheduled task was created.
AnswerA

Event ID 4648 is logged when a process explicitly supplies alternate credentials for a logon, such as RunAs or scheduled tasks using stored credentials. It records the target account and the subject account, distinguishing it from ordinary interactive logons.

Why this answer

Windows Security Event ID 4648 indicates that a logon attempt was made using explicit credentials — that is, a process attempted to log on with credentials different from those of the current user. This is commonly seen when using RunAs or scheduled tasks with stored credentials. It is a key event for detecting lateral movement or credential misuse.

Exam trap

200-201 often tests the confusion between similar event IDs — candidates may pick 4624 (logon) or 4720 (account creation) when the question specifically asks about explicit credential use, which is 4648.

How to eliminate wrong answers

Option B is wrong because service installation is logged under Event ID 7045 (System log) or 4697 (Security log), not 4648. Option C is wrong because user account creation is Event ID 4720. Option D is wrong because scheduled task creation is Event ID 4698.

None of these correspond to 4648.

39
Multi-Selecthard

A security analyst is analyzing a Linux system suspected of being used as a phishing server. Which THREE artifacts should the analyst examine to identify persistence mechanisms? (Select 3)

Select 3 answers
A./var/log/auth.log
B./etc/systemd/system/
C./etc/rc.local
D.~/.bash_history
E./etc/crontab
AnswersB, C, E

The /etc/systemd/system/ directory holds administrator-defined systemd unit files, including custom services and timers that start automatically at boot. Examining it reveals malicious units an attacker added for persistence, satisfying the requirement to identify persistence mechanisms on the compromised Linux phishing server.

Why this answer

Common Linux persistence mechanisms include cron jobs (crontab), systemd services, and startup scripts. Bash history may show commands but is not a persistence mechanism itself.

40
MCQhard

An analyst is reviewing a memory dump and uses Volatility's cmdline plugin to view process command lines. One process shows command line arguments that include a long base64-encoded string. What should the analyst suspect?

A.The process may be running obfuscated malicious code
B.The process is benign and the string is a normal parameter
C.The string is a hash for integrity verification
D.The process is using encryption
AnswerA

Long base64-encoded command line arguments indicate encoded payloads, a common obfuscation technique used by malware to hide scripts or commands from casual inspection. Legitimate processes rarely pass such blobs as arguments, so the analyst should suspect obfuscated malicious code.

Why this answer

The presence of a long base64-encoded string in a process command line is a strong indicator of obfuscation, commonly used by malware to hide payloads or configuration data from static analysis. Base64 encoding is not encryption; it is a simple encoding scheme that can be easily decoded, but it obscures the string's content from casual inspection. Volatility's cmdline plugin reveals this artifact, and an analyst should suspect that the process is executing obfuscated malicious code, as attackers frequently use this technique to evade signature-based detection.

Exam trap

Cisco often tests the distinction between encoding and encryption, where candidates mistakenly think base64 is encryption or a hash, when it is actually a reversible encoding used for obfuscation.

How to eliminate wrong answers

Option B is wrong because a long base64-encoded string is not a normal parameter for legitimate processes; typical benign parameters are short, human-readable, and do not require encoding. Option C is wrong because a hash for integrity verification (e.g., SHA256, MD5) is a fixed-length hexadecimal string, not a variable-length base64-encoded string; base64 encoding is used for data, not hashes. Option D is wrong because encryption produces ciphertext that is not base64-encoded by default; base64 is an encoding scheme, not an encryption algorithm, and the string is obfuscated, not encrypted.

41
MCQeasy

During a host investigation on a Windows 10 endpoint, an analyst wants to review the history of commands typed into PowerShell consoles by interactive users. Which artifact should the analyst examine?

A.The PowerShell console host history file at %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
B.The Windows Prefetch directory, examining POWERSHELL.EXE-*.pf
C.The Application event log filtered for PowerShell source events
D.The Windows Security event log filtered for Event ID 4688
AnswerA

PSReadLine records every command entered in an interactive PowerShell console to ConsoleHost_history.txt under the user's AppData. It persists across sessions and shows the exact command lines typed, including paths, parameters, and any encoded strings, making it a direct record of user PowerShell activity on that host.

Why this answer

Interactive PowerShell commands are captured by the PSReadLine module, which appends each entered line to ConsoleHost_history.txt in the user's AppData roaming profile. This file survives reboots and gives investigators a chronological list of commands typed at the console, including download cradle strings and lateral-movement commands, without requiring transcription or module logging to have been enabled beforehand.

Exam trap

The trap here is assuming that PowerShell activity is only visible through event logs, when the per-user PSReadLine history file is often the richest source of typed commands.

42
MCQeasy

In Linux forensics, which file would an analyst check to see command history of a user, potentially revealing malicious commands executed?

A./etc/passwd
B./proc/net/tcp
C./var/log/auth.log
D./home/user/.bash_history
AnswerD

The per-user `.bash_history` file in the home directory records commands typed in interactive Bash sessions, directly satisfying the requirement to recover a user's command history. Unlike system-wide logs, it captures the exact command lines executed, which may expose malicious activity such as reconnaissance or privilege escalation attempts.

Why this answer

Bash history is stored in ~/.bash_history for each user.

43
MCQeasy

A security analyst is examining a Linux web server that is suspected of being compromised. The analyst runs `ps aux` and notices a process named `apache2` running as the user `www-data`, but its parent process ID (PPID) is 1 (init/systemd). Normally, `apache2` is started by a master process. What is the most likely explanation for this anomaly?

A.The `apache2` process was re-parented to init after its original parent terminated.
B.The `apache2` process is a kernel thread masquerading as a user process.
C.The `apache2` process was started by systemd as a direct child of PID 1.
D.The `apache2` process was started by a cron job.
AnswerA

When a process's parent terminates, the child is re-parented to PID 1 (init or systemd) on Linux. This can happen if the original Apache master process crashed or was killed, leaving orphaned worker processes. An attacker might also kill the parent to hide the lineage. Thus, PPID 1 for `apache2` suggests the original parent is gone, which is suspicious.

Why this answer

On Linux, when a parent process dies, its children are re-parented to PID 1 (init/systemd). An `apache2` worker with PPID 1 indicates its original parent (the Apache master) is no longer running, which is unusual and may indicate tampering or a crash. This warrants further investigation into process lineage and system logs.

Exam trap

The trap here is assuming that systemd directly starts Apache workers, when in reality a master process typically manages them, so PPID 1 suggests an orphaned process.

44
MCQeasy

A security analyst is examining a Windows 10 endpoint that is suspected of being infected with malware. The analyst runs 'Get-WinEvent -LogName Security | Where-Object {$_.Id -eq 4688}' and notices that a process named 'cmd.exe' was launched with the command line 'cmd /c vssadmin.exe delete shadows /all /quiet'. Which type of attack does this command indicate?

A.A legitimate backup operation removing old shadow copies
B.A system administrator troubleshooting disk space issues
C.A malware family using shadow copy deletion for anti-forensics
D.Ransomware deleting volume shadow copies to prevent recovery
AnswerD

The command 'vssadmin delete shadows /all /quiet' is a known technique used by ransomware to delete shadow copies, making it impossible to restore encrypted files. This is a common precursor to encryption. The use of cmd.exe to execute it is typical for scripted attacks, indicating ransomware activity.

Why this answer

The command 'vssadmin delete shadows /all /quiet' is a hallmark of ransomware, used to eliminate backup copies before encrypting files. It is often executed via cmd.exe in scripts. Detecting this command in process creation logs is a high-fidelity indicator of ransomware activity, allowing for immediate response.

Exam trap

The trap here is misinterpreting the command as a benign administrative action, ignoring the context of a suspected infection and the destructive nature of deleting all shadow copies.

45
Multi-Selectmedium

During memory analysis using Volatility, an analyst wants to identify processes that may be hiding. Which TWO plugins are most useful for detecting hidden or injected code? (Choose two.)

Select 2 answers
A.malfind
B.pslist
C.dlllist
D.psxview
E.cmdline
AnswersA, D

The malfind plugin scans process memory regions for injected code by looking for pages marked executable that lack a corresponding mapped file on disk, exposing code injection and hidden payloads. This directly satisfies the stem's requirement to detect hidden or injected code during memory analysis.

Why this answer

Option A, malfind, is correct because it scans process memory for regions with suspicious characteristics typical of injected or hidden code, such as pages marked PAGE_EXECUTE_READWRITE (RWX) or memory that is not backed by a file on disk, which is a strong indicator of code injection or process hollowing. Option D, psxview, is correct because it cross-references multiple process-listing sources (e.g., pslist, psscan, thrdscan, csrss handles, session processes) and highlights discrepancies where a process appears in some listings but not others, which is a classic sign of a hidden process. Option B, pslist, is not correct here because it simply walks the active process linked list and will not reveal processes that have been unlinked to hide themselves.

Option C, dlllist, is not correct because it enumerates loaded DLLs for a given process and does not by itself detect hidden processes or injected code. Option E, cmdline, is not correct because it only retrieves process command-line arguments and provides no mechanism for detecting hidden or injected code.

Exam trap

200-201 often tests the difference between plugins that list processes (pslist) and those that detect hidden processes (psxview) or injected code (malfind); candidates must remember that pslist alone cannot reveal hidden processes.

46
MCQmedium

An analyst is investigating a Linux system and wants to view the current network connections. Which command is most appropriate to list listening TCP ports along with the associated processes?

A.netstat -anp
B.cat /proc/net/tcp
C.lsof -i TCP
D.ss -tlnp
AnswerD

The ss command with -tlnp lists TCP sockets in listening state, numeric ports, and the owning process. It reads kernel socket tables directly, making it faster than netstat and satisfying the requirement to show listening TCP ports with associated processes.

Why this answer

'ss -tlnp' lists TCP (-t) listening (-l) sockets with numeric ports (-n) and the owning process (-p), which is exactly what the analyst needs. The ss utility reads kernel netlink sockets directly, making it faster and more accurate than netstat on modern Linux systems.

Exam trap

The trap is choosing netstat out of habit — the exam expects recognition that ss is the modern, preferred tool for socket enumeration on Linux, and that -tlnp specifically filters listening TCP with processes.

How to eliminate wrong answers

Option A is wrong because 'netstat -anp' shows all sockets (listening and established) with numeric addresses and processes, but it is deprecated on many distributions and less precise than ss for filtering listening TCP ports. Option B is wrong because 'cat /proc/net/tcp' shows raw kernel TCP table entries in hex with no process mapping and no human-readable port names. Option C is wrong because 'lsof -i TCP' lists all TCP connections (not just listening) and requires parsing to isolate listeners.

47
Multi-Selectmedium

A security analyst is investigating a Linux host for signs of compromise. The analyst runs `ps aux` and notices a process named `kworker` with a high CPU usage. The analyst suspects this may be a masquerading malware process. Which TWO commands should the analyst use to verify whether this process is legitimate or malicious? (Choose two.)

Select 2 answers
A.`ls -l /proc/<PID>/exe` to check the executable path
B.`df -h` to check disk usage
C.`netstat -tulpn` to list all listening ports
D.`top -c` to view the process list with command lines
E.`cat /proc/<PID>/cmdline` to view the command line arguments
AnswersA, E

The /proc/<PID>/exe symlink points to the actual executable file. For a legitimate kernel worker, this link is typically absent or points to nothing because kernel threads have no user-space executable. If it points to a file in /tmp or another suspicious location, it indicates a masquerading process. This is a quick and effective check.

Why this answer

Legitimate kernel worker threads (kworker) have no user-space executable and an empty cmdline. Checking /proc/<PID>/exe reveals if the process points to a real binary, and /proc/<PID>/cmdline shows the command line. If either indicates a user-space path or non-empty arguments, the process is likely masquerading.

These two checks together provide strong evidence.

Exam trap

The trap here is relying on process names alone, which can be spoofed, instead of verifying the underlying executable and command line via /proc.

48
MCQeasy

Which Windows Prefetch file extension indicates that a program has been executed on the system?

A..evtx
B..pf
C..tmp
D..log
AnswerB

Windows writes a .pf Prefetch file into C:\Windows\Prefetch each time an executable launches, recording the binary name, run count and timestamps. Its presence therefore proves execution, unlike .lnk shortcuts or registry keys, which merely evidence access or configuration.

Why this answer

Prefetch files with the .pf extension are created by Windows when a program is executed, storing metadata about the executable's loading and execution. The presence of a .pf file in C:\Windows\Prefetch is a strong indicator that the program ran on the system. This makes .pf the correct extension for indicating program execution.

Exam trap

200-201 often tests the confusion between Prefetch (.pf) and other forensic artifacts like Event Logs (.evtx) — candidates may pick .evtx because it records events, but .pf specifically indicates program execution.

How to eliminate wrong answers

Option A is wrong because .evtx is the extension for Windows Event Log files, which record system and application events but are not specific to program execution tracking. Option C is wrong because .tmp files are temporary files created by various processes and do not indicate execution. Option D is wrong because .log files are generic text logs and are not the Prefetch file format.

49
Multi-Selecthard

An analyst is analyzing a Linux system that may have been compromised. Which THREE artifacts would provide evidence of attacker activity? (Choose three.)

Select 3 answers
A./proc/cpuinfo
B./var/spool/cron/crontabs/
C./etc/passwd
D./var/log/auth.log
E./home/user/.bash_history
AnswersB, D, E

The /var/spool/cron/crontabs/ directory holds per-user cron schedules on Linux, so any malicious job an attacker added for persistence appears here as a readable file. This directly satisfies the stem's requirement for evidence of attacker activity, revealing scheduled commands that re-establish access or execute payloads after reboot.

Why this answer

Option B, /var/spool/cron/crontabs/, is correct because attackers commonly establish persistence by adding malicious cron jobs here (per-user crontabs on Debian/Ubuntu systems), so unexpected entries provide direct evidence of attacker activity. Option D, /var/log/auth.log, is correct because it records authentication events such as SSH logins, sudo usage, and failed/successful password attempts, which can reveal unauthorized access or brute-force activity. Option E, /home/user/.bash_history, is correct because it preserves the commands a user (or an attacker operating under that account) executed, often exposing reconnaissance, privilege escalation, or data exfiltration commands.

Option A, /proc/cpuinfo, is not relevant because it only exposes CPU hardware details from the kernel and contains no record of user or attacker actions. Option C, /etc/passwd, is not the best evidence of activity because it is a static account database listing users; while tampering (e.g., a rogue UID 0 account) could be suspicious, the file itself does not log activity, and the question asks for artifacts evidencing attacker activity.

Exam trap

The trap is confusing general system files with forensic artifacts; candidates might select /etc/passwd because it relates to user accounts, but it is not as indicative of active attacker activity as the other three.

50
Multi-Selecthard

An analyst is investigating a Windows host and observes a suspicious process with PID 1337. Which THREE of the following Volatility commands would provide useful information about this process? (Choose three.)

Select 3 answers
A.cmdline
B.hivelist
C.pslist
D.connscan
E.dlllist
AnswersA, C, E

Correct. Shows command-line arguments for the process.

Why this answer

The `cmdline` plugin displays the command-line arguments used to start a process, which is critical for identifying malicious or suspicious execution patterns (e.g., obfuscated paths, encoded commands). For PID 1337, this reveals exactly how the process was launched, helping to confirm or refute malicious intent.

Exam trap

Cisco often tests the distinction between process-specific plugins (like `cmdline`, `dlllist`, `pslist`) and system-wide or network plugins (like `hivelist`, `connscan`), leading candidates to select plugins that are useful for general analysis but not directly for investigating a specific process.

51
MCQhard

A security analyst is analyzing a suspicious PE file. Using a hex editor, the analyst sees the MZ header (4D 5A). The file's entropy is calculated as 7.8. What does the high entropy most likely indicate?

A.The file is a legitimate signed binary
B.The file is likely packed or obfuscated
C.The file is corrupted
D.The file contains mostly plain text strings
AnswerB

Entropy near 7.8 approaches the theoretical maximum for byte data, indicating compressed or encrypted content rather than readable code. Packers and obfuscators compress or encrypt the payload, so high entropy in a PE file suggests packing.

Why this answer

High entropy (close to 8) suggests the file is packed or encrypted, as compressed or encrypted data has high randomness. This is often used by malware to evade signature detection.

52
MCQeasy

A security analyst is examining a Linux host and wants to identify which user account was used to execute a specific command that modified a critical system file. Which of the following files would provide the MOST direct evidence of the user who executed the command?

A./var/log/auth.log
B./var/log/syslog
C./var/log/audit/audit.log
D./home/<user>/.bash_history
AnswerC

The audit log, when auditd is configured, records detailed system call and command execution events, including the user ID (UID) and effective user ID (EUID) of the process that executed the command. This provides direct evidence of which user account was used to run the command, making it the most reliable source for this scenario.

Why this answer

The audit log, managed by auditd, is designed to capture security-relevant events, including command execution with user context. It logs the UID and EUID, so an analyst can determine exactly which user account executed the command that modified the critical file. Other logs may not capture this level of detail.

Exam trap

The trap here is assuming that bash_history or auth.log will show the command and user, but bash_history is per-user and modifiable, while auth.log only shows authentication events.

53
Multi-Selectmedium

A security analyst is reviewing a Windows host for indicators of credential dumping. The analyst wants to identify artifacts that commonly indicate tools such as Mimikatz have been used on the system. Which two artifacts should the analyst look for? (Choose two.)

Select 2 answers
A.Security Event ID 4656 or 4663 referencing lsass.exe with unusual access rights
B.An increase in Windows Defender signature definition version numbers
C.Presence of a driver named SysmonDrv.sys in the System32\drivers directory
D.Event ID 4688 showing the launch of notepad.exe by the SYSTEM account
E.Creation of a memory dump file such as lsass.dmp in a user-writable directory
AnswersA, E

Security Event IDs 4656 and 4663 record handle requests and object access, and when they reference lsass.exe with rights such as PROCESS_VM_READ, they strongly suggest a tool attempted to read credential material from LSASS memory. This is a classic indicator of credential dumping activity on a Windows host.

Why this answer

Credential dumping targets LSASS memory, so the most reliable host artifacts are security events showing unusual handle access to lsass.exe and the presence of a memory dump file such as lsass.dmp in a user-writable location. Together these indicate that a tool attempted to extract credentials from LSASS on the endpoint.

Exam trap

The trap here is selecting generic or benign system artifacts like Sysmon driver presence or Defender updates, which are unrelated to the LSASS-access behavior that credential dumping produces.

54
Multi-Selecthard

A Linux server has been compromised. The analyst checks for persistence mechanisms. Which THREE of the following are common Linux persistence techniques that should be examined? (Select THREE)

Select 3 answers
A.Creating a systemd service unit
B.Cron jobs in /etc/crontab or user crontabs
C.Changing the system timezone
D.Adding SSH public keys to authorized_keys
E.Modifying the /etc/hosts file
AnswersA, B, D

Systemd services can start automatically on boot.

Why this answer

Creating a systemd service unit is a common Linux persistence technique because systemd is the default init system for most modern Linux distributions. An attacker can place a malicious service file (e.g., /etc/systemd/system/evil.service) that automatically starts the malware at boot or after a crash, ensuring continued access even after a reboot.

Exam trap

Cisco often tests the distinction between persistence (automatic code execution) and other system modifications; the trap here is confusing a configuration change (timezone or hosts file) with a mechanism that ensures malware runs repeatedly.

55
MCQmedium

An analyst uses 'sc query' on a Windows host and finds a service named 'WindowsUpdate' with a binary path pointing to 'C:\Users\Public\update.exe'. The service is running. Why is this suspicious?

A.The service is running
B.The service name is misspelled
C.The service displays 'WindowsUpdate'
D.The binary path is not in a system directory
AnswerD

Legitimate Windows services almost always execute from protected system locations such as C:\Windows\System32, not user-writable directories. C:\Users\Public is world-writable, allowing any local user to replace update.exe and gain persistence with SYSTEM privileges, since the service runs under a privileged account. This path anomaly satisfies the stem's suspicion constraint.

Why this answer

Legitimate Windows services, especially those mimicking system components like Windows Update, should have their binary paths in protected system directories (e.g., C:\Windows\System32). A binary path pointing to C:\Users\Public\update.exe indicates the executable is in a user-writable location, which is a common technique used by malware to evade detection and maintain persistence. The 'sc query' command reveals the service configuration, and this abnormal path is a strong indicator of compromise.

Exam trap

Cisco often tests the misconception that a service name or display name alone is the red flag, when in fact the critical indicator is the binary path location outside of system directories.

How to eliminate wrong answers

Option A is wrong because a service being running is not inherently suspicious; many legitimate services run continuously. Option B is wrong because the service name 'WindowsUpdate' is not misspelled; it matches the expected name for the Windows Update service. Option C is wrong because the service displaying 'WindowsUpdate' is expected behavior for a service named that; the suspicious element is the binary path, not the display name.

56
MCQmedium

An analyst is reviewing Windows Event Logs and sees multiple Event ID 4625 entries from a single IP address. What does this indicate?

A.A user account was locked out.
B.A brute-force password guessing attack.
C.A service account password expired.
D.Successful remote logins from that IP.
AnswerB

Event ID 4625 records a failed logon attempt. Many such entries originating from one IP address indicate repeated authentication failures, the signature of a brute-force password guessing attack, rather than a single mistyped password or a successful compromise.

Why this answer

Event ID 4625 in Windows Security logs indicates a failed logon attempt. Multiple such events from a single IP address suggest a brute-force password guessing attack, where an attacker repeatedly tries different passwords. This pattern is a classic indicator of compromise.

Exam trap

The trap is confusing Event ID 4625 with other logon-related events like 4624 (success) or 4740 (lockout); candidates might also think multiple failures indicate a lockout, but lockout is a separate event.

How to eliminate wrong answers

Option A is wrong because account lockout is typically indicated by Event ID 4740 (A user account was locked out), not 4625. Option C is wrong because a service account password expiration would generate a different event, such as 4625 with a specific status code, but multiple 4625s from one IP more strongly indicate brute force. Option D is wrong because successful logins are Event ID 4624, not 4625.

57
MCQeasy

A security analyst is investigating a Windows host and wants to view running processes along with their parent-child relationships and command-line arguments. Which tool is best suited for this task?

A.Volatility
B.tasklist
C.Process Explorer
D.Task Manager
AnswerC

Process Explorer displays a live process tree showing parent-child relationships, and its properties pane exposes full command-line arguments for each process. Task Manager and basic tasklist lack this combined hierarchical and command-line visibility, meeting the analyst's investigative requirement.

Why this answer

Process Explorer provides detailed process information including parent PID and command line, while Task Manager and tasklist show limited details. Volatility is a memory analysis tool, not for live host analysis.

58
MCQhard

During an incident response engagement, an analyst is examining a Windows Server 2019 host that is suspected of being compromised. The analyst wants to determine which user accounts were used to log on interactively to the console in the last 24 hours. Which Windows artifact should the analyst query to obtain this information?

A.Security Event ID 4672 with Logon Type 2
B.Security Event ID 4624 with Logon Type 3
C.Security Event ID 4634 with Logon Type 2
D.Security Event ID 4624 with Logon Type 2
AnswerD

Security Event ID 4624 records successful logons, and Logon Type 2 specifically indicates an interactive logon at the console. Filtering 4624 events by Logon Type 2 and the desired time window gives the analyst exactly the list of accounts used for interactive console access on the server.

Why this answer

Successful interactive logons at the console are recorded as Security Event ID 4624 with Logon Type 2. Filtering for that combination and the last 24 hours gives the analyst the specific accounts used for interactive console access on the server, which is exactly the requested scope.

Exam trap

The trap here is mixing up logon type numbers, especially selecting Logon Type 3 for network access or using 4634, which records logoffs rather than successful logons.

59
MCQmedium

An analyst is investigating a Windows 10 workstation suspected of being compromised. The analyst runs `wmic process get name,processid,parentprocessid,commandline` and observes a process named `powershell.exe` with the command line `powershell -nop -w hidden -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAA...`. What does the `-enc` parameter indicate about how the command was executed?

A.The command was encrypted with AES and requires a key to decrypt.
B.The command was signed with a digital certificate to appear legitimate.
C.The command was Base64-encoded to obfuscate its contents.
D.The command was compressed using gzip to reduce its size.
AnswerC

The `-enc` parameter (short for `-EncodedCommand`) tells PowerShell to interpret the following string as Base64-encoded UTF-16LE text. Attackers use this to hide malicious scripts from command-line logging and casual inspection. Decoding the Base64 string reveals the actual PowerShell commands, which often download or execute further payloads.

Why this answer

The `-enc` parameter in PowerShell stands for `-EncodedCommand`, which accepts a Base64-encoded string representing the actual command. Attackers use it to obfuscate malicious scripts and bypass simple command-line logging. An analyst should decode the Base64 string to reveal the true intent, such as downloading a payload or establishing persistence.

Exam trap

The trap here is assuming that `-enc` means encryption requiring a decryption key, when it actually refers to Base64 encoding that anyone can decode.

60
MCQmedium

An analyst runs Volatility's pstree plugin on a memory dump. The output shows that a process 'svchost.exe' is the child of 'explorer.exe'. What is suspicious about this?

A.explorer.exe should not have any child processes
B.Nothing, svchost.exe can be a child of any process
C.svchost.exe should be a child of services.exe, not explorer.exe
D.The pstree output is unreliable
AnswerC

Legitimate svchost.exe instances are spawned by services.exe, which hosts service DLLs. A parent of explorer.exe indicates process injection or masquerading, since explorer.exe never launches service hosts. This parent-child anomaly is the specific indicator the analyst must flag.

Why this answer

In a normal Windows system, svchost.exe is a service host process that should always be a child of services.exe, which is the Service Control Manager (SCM). When svchost.exe appears as a child of explorer.exe, it indicates that a malicious process or attacker has spawned a fake svchost.exe from explorer.exe to evade detection, as legitimate svchost.exe instances are never launched from the Windows shell.

Exam trap

Cisco often tests the misconception that svchost.exe can be a child of any process because it is a common system process, but the trap is that candidates forget the strict parent-child relationship enforced by the Service Control Manager in Windows.

How to eliminate wrong answers

Option A is wrong because explorer.exe can and does have legitimate child processes, such as when a user launches an application from the Start menu or desktop; the statement that it should have no child processes is false. Option B is wrong because svchost.exe should never be a child of any arbitrary process; it must be a direct child of services.exe to be legitimate, as the SCM is the only authorized parent for service host processes. Option D is wrong because the pstree plugin from Volatility is a reliable tool for reconstructing process parent-child relationships from memory dumps; its output is trustworthy when the memory image is intact and properly analyzed.

61
MCQhard

A forensic analyst uses Volatility on a memory dump and runs the 'malfind' plugin. The output shows a process with a VAD region that has PAGE_EXECUTE_READWRITE protection and contains the pattern 'MZ'. What does this indicate?

A.The process has been infected with code injection, likely a PE executable mapped in memory.
B.The process is using a packed executable that was unpacked in memory.
C.The process has a heap spray attack, but not necessarily injected code.
D.The process is a legitimate browser with dynamic code.
AnswerA

A PAGE_EXECUTE_READWRITE VAD containing 'MZ' reveals a PE header mapped into memory, the signature of injected executable code. Legitimate modules are not both writable and executable, so this satisfies the stem's request to interpret the malfind output.

Why this answer

PAGE_EXECUTE_READWRITE protection combined with 'MZ' header suggests code injection, where a malicious executable has been written into the process memory.

62
MCQmedium

A SOC analyst is reviewing a Windows 10 endpoint after a suspected compromise. They need to determine which user account was responsible for a specific process that was launched shortly before the alert. Which Windows artifact directly records the user account associated with process creation events and should be queried using Windows Event Log?

A.Security Event ID 4625 with the Account Name field
B.System Event ID 7045 with the ServiceName field
C.Application Event ID 1000 with the Faulting application name field
D.Security Event ID 4688 with the associated user account field
AnswerD

Security Event ID 4688 is generated when a new process is created and, when process creation auditing is enabled, includes the 'SubjectUserName' and 'TargetUserName' fields that identify the account that initiated the process. This directly answers the analyst's need to attribute process execution to a specific user account on the endpoint.

Why this answer

When process creation auditing is enabled, Windows logs Security Event ID 4688 for each new process, and the event includes the subject user name that initiated it. Correlating the process name and timestamp in 4688 with the alert time lets the analyst attribute the suspicious process to a specific user account, which is exactly what is needed here.

Exam trap

The trap here is confusing process creation auditing with logon auditing, so candidates pick 4625 or 7045 when the question specifically asks for the user tied to a launched process.

63
MCQmedium

A SOC analyst receives an alert about a Windows workstation that may be infected with malware. The analyst wants to examine the system's boot configuration to determine if the malware modified boot settings to disable driver signature enforcement. Which Windows tool should the analyst use to view the current boot configuration data?

A.regedit
B.msconfig
C.sigverif
D.bcdedit
AnswerD

bcdedit is the correct tool to view and modify Windows Boot Configuration Data (BCD). It displays settings such as nointegritychecks and testsigning, which, if enabled, disable driver signature enforcement. An analyst can run 'bcdedit /enum' to inspect these values and determine if malware altered boot settings to load unsigned drivers.

Why this answer

The correct tool is bcdedit, which manages Windows Boot Configuration Data. Malware often modifies BCD settings such as nointegritychecks or testsigning to bypass driver signature enforcement and load malicious drivers. Inspecting BCD with bcdedit /enum reveals these modifications.

Other tools like msconfig, regedit, or sigverif do not provide direct access to BCD settings, making them unsuitable for this task.

Exam trap

The trap here is confusing general system configuration tools like msconfig with the specific utility that manages boot configuration data, bcdedit.

64
MCQhard

A security analyst is analyzing a memory dump from a compromised Windows system using Volatility. Which command would best reveal hidden or injected code within a process?

A.vol.py netscan
B.vol.py pslist
C.vol.py malfind
D.vol.py dlllist
AnswerC

The malfind plugin scans process memory for pages exhibiting characteristics of injected or hidden code, such as executable permissions combined with no file backing on disk. This directly targets the scenario's goal of revealing injected code within a process from the memory dump.

Why this answer

The vol.py malfind command in Volatility scans process memory for hidden or injected code by looking for memory regions with suspicious characteristics, such as executable permissions and no corresponding file on disk. It is specifically designed to detect code injection and rootkit-like behavior. This makes it the best choice for revealing hidden or injected code within a process.

Exam trap

200-201 often tests the confusion between process listing (pslist) and memory analysis (malfind) — candidates may pick pslist because it shows processes, but it does not reveal injected code hidden within a legitimate process.

How to eliminate wrong answers

Option A is wrong because netscan lists network connections and sockets, which helps identify command-and-control traffic but does not detect injected code. Option B is wrong because pslist enumerates active processes from the process list, which may miss hidden processes and does not analyze memory for injected code. Option D is wrong because dlllist lists loaded DLLs for a process, which can show malicious DLLs but does not detect injected shellcode or memory-resident code without a file.

65
MCQeasy

Which Windows Event ID corresponds to a successful user logon?

A.4648
B.4776
C.4625
D.4624
AnswerD

Event ID 4624 is written to the Windows Security log whenever an account successfully authenticates, capturing logon type, account name and source. It is the definitive indicator of a successful user logon, unlike 4625, which records failures.

Why this answer

Event ID 4624 is correct because Windows Security auditing logs 4624 for a successful account logon, including the logon type (interactive, network, service, etc.) and the account and workstation involved. It is the canonical event analysts filter on to confirm successful authentication.

Exam trap

The trap is confusing 4624 (successful logon) with 4625 (failed logon) or 4648 (explicit credential use), since all three involve authentication and differ by only a few digits.

How to eliminate wrong answers

Option A is wrong because 4648 indicates a logon was attempted using explicit credentials, such as RunAs or a mapped drive with alternate credentials, not a normal successful logon. Option B is wrong because 4776 is generated by the NTLM credential validation process on the authenticating domain controller, recording credential validation rather than a completed logon session. Option C is wrong because 4625 records a failed logon attempt, the opposite of what the question asks.

66
MCQmedium

A security analyst is reviewing a Windows 10 endpoint that is suspected of being compromised. The analyst opens Task Manager and notices a process named 'lsass.exe' running with a PID of 1234, but its parent process is 'cmd.exe' rather than 'wininit.exe'. The analyst also observes that the process path is 'C:\Users\Public\lsass.exe'. Which type of attack is most likely indicated by these findings?

A.Rootkit infection
B.Process hollowing
C.Process masquerading
D.DLL injection
AnswerC

Process masquerading occurs when malware names its executable after a legitimate system process, such as lsass.exe, but runs from an unusual location and with an unexpected parent. Here, the path 'C:\Users\Public\lsass.exe' and parent 'cmd.exe' are clear indicators that this is a fake lsass.exe, not the genuine one that runs from System32 and is spawned by wininit.exe.

Why this answer

The genuine lsass.exe runs from C:\Windows\System32 and is spawned by wininit.exe. A process named lsass.exe running from C:\Users\Public with cmd.exe as its parent is a strong indicator of process masquerading, where malware mimics a legitimate process name to evade detection. This technique is commonly used by attackers to blend in with normal system activity.

Exam trap

The trap here is assuming that any process with a legitimate name is safe, but the path and parent process are critical for verification.

67
MCQmedium

An analyst uses Volatility's 'netscan' on a memory dump and finds an established connection to an external IP on port 4444. Which type of activity is this commonly associated with?

A.Email communication
B.DNS query
C.Reverse shell or backdoor
D.Normal web browsing
AnswerC

An established outbound connection to an external host on port 4444, a common Metasploit and netcat listener port, indicates a reverse shell or backdoor. The compromised host initiated the session, letting the attacker bypass inbound firewall rules.

Why this answer

Port 4444 is commonly used by Metasploit and other remote access tools for reverse shells. An established connection to an external IP on this port is indicative of a backdoor or command-and-control communication.

68
Multi-Selectmedium

A security analyst is investigating a Linux server that is suspected of hosting a reverse-shell backdoor. The analyst wants to identify which running process is maintaining the outbound connection and which user context it is running under. Which TWO commands would best provide this information? (Choose two.)

Select 2 answers
A.cat /etc/passwd
B.top -b -n 1
C.journalctl -u sshd --since '1 hour ago'
D.lsof -i -P -n
E.ss -tunap
AnswersD, E

lsof with -i lists open Internet sockets, -P suppresses port-name resolution, and -n suppresses hostname resolution. The output shows the owning process name, PID, user, and the remote endpoint, which is exactly what is needed to tie a suspicious outbound connection to a user and process. It complements ss by showing file descriptors and the process that opened each socket.

Why this answer

To attribute a suspicious outbound connection to a specific process and user, the analyst needs socket-to-process mapping. The ss command with -tunap and lsof with -i -P -n both provide this mapping by listing open sockets alongside the owning process and user. Static files such as /etc/passwd, resource monitors like top, and service logs from journalctl do not tie live connections to processes, so they cannot identify the reverse shell.

Exam trap

The trap here is choosing commands that show system state or accounts without socket-to-process mapping, such as top or /etc/passwd, which cannot identify the process holding a reverse-shell connection.

69
MCQmedium

An analyst is reviewing a Linux host that is suspected of being compromised. The analyst runs 'ls -l /proc/1234/exe' and sees that the symbolic link points to '/tmp/.hidden/backdoor'. The process with PID 1234 is owned by root and was started from an unknown parent process. Which of the following best describes what the analyst has discovered?

A.The process is a kernel thread that has been incorrectly linked to a user-space file.
B.The process is a legitimate system daemon that has been relocated to /tmp for performance reasons.
C.The process is a containerized application that uses /tmp as its working directory.
D.The process is a malicious binary running from a non-standard location, indicating a potential compromise.
AnswerD

The /proc/1234/exe link points to the executable file of the process. A root-owned process running from /tmp/.hidden/backdoor is highly suspicious because /tmp is commonly used by attackers to drop and execute malware, and the hidden directory name suggests an attempt to avoid casual observation. This is a clear indicator of compromise.

Why this answer

The /proc/PID/exe symbolic link reveals the actual executable file backing a running process. A root-owned process executing from a hidden directory under /tmp is a classic sign of malware or an attacker's backdoor, as legitimate system processes rarely reside there. This discovery warrants immediate further investigation, such as examining the binary and its network connections.

Exam trap

The trap here is assuming that any process running from /tmp is automatically malicious, but in this context the combination of root ownership, hidden directory, and unknown parent strongly indicates compromise.

70
MCQmedium

A security analyst suspects that a Windows workstation was compromised by malware that schedules a recurring task to maintain persistence. The analyst opens Task Scheduler and sees dozens of scheduled tasks. Which built-in command-line utility should the analyst use to export a detailed list of all scheduled tasks, including the actions they perform, so the list can be reviewed offline?

A.schtasks /query /fo LIST /v
B.tasklist /v /fo csv
C.wmic startup list full
D.sc query type= service state= all
AnswerA

schtasks with /query lists scheduled tasks, /fo LIST selects a list format, and /v adds verbose details such as the task's action, trigger, author, and run-as account. This gives the analyst the full configuration needed to spot a malicious recurring task offline without clicking through the GUI.

Why this answer

Scheduled tasks are a common persistence mechanism because they can launch a payload on a schedule or at logon. The schtasks utility is the native command-line interface to the Task Scheduler service, and the /query /fo LIST /v combination produces a verbose, exportable inventory of every task, including its action and trigger. That output can be reviewed offline to identify the malicious recurring task.

Exam trap

The trap here is confusing process enumeration with scheduled-task enumeration, since tasklist and schtasks have similar-sounding names but query completely different subsystems.

71
MCQmedium

In a Linux system, an analyst wants to check for unauthorized cron jobs. Which of the following is a common location for user-specific cron jobs?

A./var/log/cron
B./etc/cron.d/
C./etc/crontab
D./var/spool/cron/crontabs/
AnswerD

On Linux, user-specific cron jobs are stored per-account in /var/spool/cron/crontabs/, with one file per user. Inspecting this directory reveals unauthorised scheduled tasks created by individual accounts, which is exactly what the analyst needs to check.

Why this answer

User-specific cron jobs are stored in /var/spool/cron/crontabs/ (or /var/spool/cron/ on some distributions), named after the user.

72
MCQmedium

An analyst finds an unknown scheduled task on a Windows system that runs a PowerShell script at system startup. Which tool is best for examining the task's trigger and actions?

A.Services.msc
B.Event Viewer
C.Registry Editor
D.Task Scheduler
AnswerD

Task Scheduler exposes each task's triggers, actions, conditions and author, letting the analyst inspect exactly what the PowerShell script runs and when. Other tools show process or file artefacts but not the task definition itself.

Why this answer

Task Scheduler is the native Windows tool that displays scheduled tasks along with their triggers (e.g., 'At system startup') and actions (e.g., running a PowerShell script). It provides a GUI and command-line interface (schtasks) to inspect, modify, or disable suspicious tasks, making it the best fit for examining the task's configuration.

Exam trap

The trap is assuming Event Viewer or Registry Editor is sufficient because they can show evidence a task ran; the question asks specifically for examining the task's trigger and actions, which only Task Scheduler presents directly.

How to eliminate wrong answers

Option A is wrong because Services.msc manages Windows services and their startup types, not scheduled tasks, so it would not reveal the PowerShell script or its trigger. Option B is wrong because Event Viewer shows logged events and audit records, which can indicate that a task ran but does not display the task's trigger or action definitions. Option C is wrong because Registry Editor can show task-related keys under TaskCache, but it is not the purpose-built tool for viewing triggers and actions and is error-prone for this use case.

73
MCQhard

An analyst is triaging a Windows 10 host and finds a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from C:\Users\Public\update.ps1 every 30 minutes. The script base64-decodes a payload and calls Invoke-WebRequest to a remote host. Which action should the analyst take FIRST to preserve evidence while containing the threat?

A.Immediately reboot the host into Safe Mode to stop the PowerShell execution, then begin collecting forensic artifacts from the disk.
B.Run a full antivirus scan and allow it to quarantine any detected files, then review the scheduled task XML for indicators.
C.Delete the scheduled task and the update.ps1 file immediately, then capture a memory image of the host for offline analysis.
D.Capture volatile data including the running process list, network connections, and the contents of C:\Users\Public\update.ps1, then disable the scheduled task and isolate the host.
AnswerD

Volatile artifacts such as memory-resident processes, active network connections, and the malicious script file can disappear on reboot or be deleted by the attacker. Capturing them first preserves evidence for later analysis. Only after acquisition should the analyst disable the task and isolate the host to stop reinfection. This order follows the standard order of volatility principle in incident response.

Why this answer

The order of volatility dictates that the most perishable evidence (memory, network state, running processes) is captured before less volatile evidence (disk files) and before any remediation. Capturing the script, process list, and connections first preserves investigative value; disabling the task and isolating the host then stops the beaconing without destroying evidence. Reboots, AV quarantine, and deletion all destroy or alter artifacts needed to scope the compromise.

Exam trap

The trap here is jumping straight to remediation actions such as rebooting, deleting the task, or running antivirus, which destroy volatile evidence before it can be captured.

74
MCQmedium

A Windows system's security log shows Event ID 4720 followed by 4726 for the same username within minutes. What does this sequence indicate?

A.A user changed their password.
B.The account was successfully logged on.
C.A group membership was changed.
D.An account was created and then deleted, possibly for short-term unauthorized access.
AnswerD

Event ID 4720 logs account creation and 4726 logs account deletion. Occurring minutes apart for the same username, the pair indicates an account was provisioned then removed, a pattern consistent with an attacker creating a temporary backdoor account for short-lived unauthorised access.

Why this answer

Event ID 4720 indicates a user account was created, and 4726 indicates it was deleted. The short interval suggests the account was created for temporary access, possibly malicious, and then removed to cover tracks.

Exam trap

The trap is confusing account creation/deletion events with other account-related events like password changes or logons, leading to incorrect interpretation.

How to eliminate wrong answers

Option A is wrong because password changes generate Event ID 4723 or 4724. Option B is wrong because successful logons generate Event ID 4624. Option C is wrong because group membership changes generate Event IDs 4728, 4732, etc.

75
MCQeasy

Which Windows Event ID is recorded when a user account is created, indicating potential unauthorized account creation?

A.4726
B.4648
C.4624
D.4720
AnswerD

Event ID 4720 is logged in the Windows Security log whenever a user account is created. Monitoring for it surfaces unauthorised account creation, since legitimate provisioning should be attributable to known administrators or automated processes.

Why this answer

Windows Security Event ID 4720 is logged when a user account is created. It is a key indicator for detecting unauthorized account creation, which attackers use for persistence and privilege escalation. This directly matches the question.

Exam trap

200-201 often tests Windows Event ID memorization — candidates confuse 4720 (account created) with 4726 (account deleted) or 4624 (logon), so precise ID-to-action mapping is essential.

How to eliminate wrong answers

Option A is wrong because Event ID 4726 records user account deletion, not creation. Option B is wrong because Event ID 4648 indicates a logon attempt using explicit credentials (e.g., runas), which is a credential-use event, not account creation. Option C is wrong because Event ID 4624 records a successful logon, which is authentication activity, not account creation.

Page 1 of 2 · 118 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cbrops Host Analysis questions.