Courseiva
easyMultiple Select

200-201 Practice Question: Which TWO host-based analysis techniques are most…

Which TWO host-based analysis techniques are most effective for detecting fileless malware?

⚠ Common exam trap

Cisco often tests the distinction between host-based and network-based analysis techniques, and the trap here is that candidates may select network traffic analysis (B) because it can detect fileless malware's network activity, but the question specifically asks for host-based techniques, making B incorrect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Process memory analysis to detect injected code

Option A is correct because fileless malware typically executes in memory (e.g., via reflective DLL injection, process hollowing, or shellcode injection) without writing a malicious file to disk, so examining process memory for injected code, unbacked executable regions, or anomalous modules is one of the most effective host-based detection techniques. Option E is correct because fileless attacks frequently abuse PowerShell and other scripting engines, and PowerShell script block logging (Event ID 4104) records the actual script content executed, exposing malicious commands that never touch the filesystem. Option B is not a host-based technique and, while useful for command-and-control detection, cannot directly reveal in-memory code injection. Option C is ineffective against fileless malware because signature-based scanning relies on malicious files on disk, which fileless attacks avoid. Option D can reveal persistence mechanisms, but registry artifacts alone are not the most effective means of detecting fileless execution, which occurs in memory and via scripting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Process memory analysis to detect injected code

    Why this is correct

    Process memory analysis detects fileless malware by inspecting a running process's address space for injected code, reflective DLL loading, or shellcode that never touches disk. This directly satisfies the stem's constraint: fileless threats reside only in memory, so scanning RAM reveals malicious regions that file-based signature scanning would miss entirely.

  • ✗

    Network traffic analysis

    Why it's wrong here

    Network traffic analysis inspects packets on the wire, so it cannot see fileless malware that resides only in memory and never generates distinctive network signatures. It is tempting because it excels at detecting command-and-control beaconing and data exfiltration, and would be correct where malicious traffic crosses the network boundary.

  • ✗

    Signature-based file scanning

    Why it's wrong here

    Fileless malware executes in memory, often via PowerShell or WMI, leaving no file on disk for signatures to hash or match. Signature scanning is tempting because it is fast and effective against known file-borne threats, but it cannot detect what never touches the filesystem.

  • ✗

    Registry analysis for persistence

    Why it's wrong here

    Registry analysis targets persistence mechanisms written to registry keys, but fileless malware executes in memory via PowerShell or WMI and may leave no registry footprint at all. It is tempting because registry run keys are a classic persistence location, and it would be correct for detecting malware that establishes autostart entries.

  • ✓

    PowerShell script block logging

    Why this is correct

    Fileless malware executes in memory via PowerShell, leaving few files on disk. Script block logging records the actual PowerShell code executed, capturing malicious commands that process-creation or file-based telemetry would miss, directly satisfying the detection requirement.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.