easyMultiple Select
200-201 Practice Question: Which TWO host-based analysis techniques are most…
Which TWO host-based analysis techniques are most effective for detecting fileless malware?
⚠ Common exam trap
Cisco often tests the distinction between host-based and network-based analysis techniques, and the trap here is that candidates may select network traffic analysis (B) because it can detect fileless malware's network activity, but the question specifically asks for host-based techniques, making B incorrect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Process memory analysis to detect injected code
Option A is correct because fileless malware typically executes in memory (e.g., via reflective DLL injection, process hollowing, or shellcode injection) without writing a malicious file to disk, so examining process memory for injected code, unbacked executable regions, or anomalous modules is one of the most effective host-based detection techniques. Option E is correct because fileless attacks frequently abuse PowerShell and other scripting engines, and PowerShell script block logging (Event ID 4104) records the actual script content executed, exposing malicious commands that never touch the filesystem. Option B is not a host-based technique and, while useful for command-and-control detection, cannot directly reveal in-memory code injection. Option C is ineffective against fileless malware because signature-based scanning relies on malicious files on disk, which fileless attacks avoid. Option D can reveal persistence mechanisms, but registry artifacts alone are not the most effective means of detecting fileless execution, which occurs in memory and via scripting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Process memory analysis to detect injected code
Why this is correct
Process memory analysis detects fileless malware by inspecting a running process's address space for injected code, reflective DLL loading, or shellcode that never touches disk. This directly satisfies the stem's constraint: fileless threats reside only in memory, so scanning RAM reveals malicious regions that file-based signature scanning would miss entirely.
- ✗
Network traffic analysis
Why it's wrong here
Network traffic analysis inspects packets on the wire, so it cannot see fileless malware that resides only in memory and never generates distinctive network signatures. It is tempting because it excels at detecting command-and-control beaconing and data exfiltration, and would be correct where malicious traffic crosses the network boundary.
- ✗
Signature-based file scanning
Why it's wrong here
Fileless malware executes in memory, often via PowerShell or WMI, leaving no file on disk for signatures to hash or match. Signature scanning is tempting because it is fast and effective against known file-borne threats, but it cannot detect what never touches the filesystem.
- ✗
Registry analysis for persistence
Why it's wrong here
Registry analysis targets persistence mechanisms written to registry keys, but fileless malware executes in memory via PowerShell or WMI and may leave no registry footprint at all. It is tempting because registry run keys are a classic persistence location, and it would be correct for detecting malware that establishes autostart entries.
- ✓
PowerShell script block logging
Why this is correct
Fileless malware executes in memory via PowerShell, leaving few files on disk. Script block logging records the actual PowerShell code executed, capturing malicious commands that process-creation or file-based telemetry would miss, directly satisfying the detection requirement.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.