Courseiva

200-201 · topic practice

Host-Based Analysis practice questions

Host-Based Analysis covers endpoint evidence collection and interpretation on Windows and Linux systems. You must identify malicious processes, persistence mechanisms, and user activity artifacts, then map findings to the correct forensic tool or file location. Questions present investigation scenarios and ask which commands, registry hives, or files reveal the needed evidence.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Host-Based Analysis

What the exam tests

What to know about Host-Based Analysis

Be able to select the right forensic artifact for a scenario: Volatility plugins for Windows memory, correct registry hives for persistence, and Linux cron and history file paths. The most important thing is matching the investigative question to the exact command or file that answers it.

Volatility plugins such as pslist, pstree, and dlllist for examining Windows process memory artifacts

Windows registry Run keys under HKCU and HKLM for user logon persistence detection

Linux user cron job locations including /var/spool/cron and crontab entries

Linux shell history files such as .bash_history for reconstructing executed commands

Watch out for

Common Host-Based Analysis exam traps

  • ▸Confusing Volatility plugins that list processes with those that dump memory or network connections, selecting irrelevant commands for process analysis.
  • ▸Assuming all Run key persistence lives in HKLM, missing per-user HKCU hives that malware commonly abuses.
  • ▸Checking only system-wide cron directories and overlooking user-specific crontab storage locations where unauthorized jobs hide.

Practice set

Host-Based Analysis questions

20 questions · select your answer, then reveal the explanation

An analyst is investigating a Windows host suspected of malware persistence. Which registry key is commonly used by malware to run a program every time a user logs in, located under both HKLM and HKCU?

During an incident response on a Linux server, an analyst runs 'ps aux' and notices a process named 'cryptominer' with high CPU usage. The process PPID is 1. Which tool would best help the analyst examine the parent-child relationship and find how the process was started?

An analyst uses Volatility to analyze a memory dump from a compromised Windows machine. Which Volatility command would show the list of running processes along with their parent process IDs?

During memory analysis with Volatility, the 'cmdline' plugin shows a process with no command-line arguments. Which plugin could help recover the original command line if it was truncated or hidden?

An analyst finds a suspicious service named 'UpdateSvc' running on a Windows system. Which tool or command would best help determine the service's binary path and start type?

A Linux analyst notices a process named '[kworker/1:1+events]' in the process list with high CPU usage. Which further analysis step would help determine if this is a legitimate kernel worker or a rootkit hiding as one?

During memory analysis with Volatility, the 'pstree' plugin shows a parent process of 'winlogon.exe' spawning 'cmd.exe'. What is the most likely explanation for this anomaly?

An analyst is examining a Windows system for evidence of privilege escalation or credential theft. Which THREE Event IDs should the analyst focus on in the Security log? (Select THREE)

An analyst discovers that a Windows system executes a payload each time a user logs in, even before the desktop appears. Which registry key is most likely used for such persistence, and why would it be harder to detect than typical Run keys?

During memory analysis using Volatility, an analyst suspects code injection. Which THREE commands would be most useful to identify injected code? (Select THREE)

An analyst is investigating a Windows host for signs of malware persistence. Which registry key would the analyst check for programs that run automatically when any user logs in?

During an incident response, a Linux system shows unusual outbound network connections from a process named 'httpd'. The analyst uses 'ss -tlnp' to examine listening sockets. Which column would most likely indicate if the process is malicious?

A security analyst is analyzing a memory dump using Volatility. The command 'volatility -f mem.dump malfind' returns several results with VAD tags 'VadS' and 'Vadl'. What does this indicate?

An analyst is using Volatility's 'pslist' and 'pstree' commands on a memory dump. The output shows a process named 'lsass.exe' with a PID of 1024. However, the usual PID for lsass.exe on this system is 512. What does this discrepancy likely indicate?

An analyst investigating a Linux host notices an unusual process running as root. Which command would provide the most detailed process listing including parent PID and CPU usage?

A Linux system administrator notices unauthorized SSH logins in /var/log/auth.log. Which of the following log entries would indicate a failed SSH login attempt?

An analyst discovers an unknown process on a Windows host that has no parent process (PPID 0). What does this likely indicate?

A security analyst is examining a Linux system suspected of compromise. Which THREE artifacts should be reviewed to identify potential persistence mechanisms?

During a host-based analysis of a Windows system, an analyst finds a suspicious executable that runs every time the system boots. Which registry key is most commonly used for this type of persistence?

During a host-based analysis, an analyst discovers a suspicious service on a Windows machine. Which tool or command can be used to query the service configuration?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Host-Based Analysis sessions

Start a Host-Based Analysis only practice session

Every question in these sessions is drawn from the Host-Based Analysis domain — nothing else.

Related practice questions

Related 200-201 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 200-201 exam test about Host-Based Analysis?
Be able to select the right forensic artifact for a scenario: Volatility plugins for Windows memory, correct registry hives for persistence, and Linux cron and history file paths. The most important thing is matching the investigative question to the exact command or file that answers it.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Host-Based Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the Host-Based Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 200-201 topics?
Use the topic links above to move to related areas, or go back to the 200-201 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 200-201 exam covers. They are not copied from any real exam or dump site.