hardMultiple Select
200-201 Practice Question: Which TWO locations in a Linux filesystem should…
Which TWO locations in a Linux filesystem should be checked for evidence of malware persistence?
⚠ Common exam trap
Cisco often tests the distinction between locations that store persistent configuration (like crontabs and init.d) versus runtime or log-only directories (like /proc and /var/log), so candidates mistakenly choose /proc or /var/log/syslog because they are commonly examined during live analysis, but they do not hold persistence artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/spool/cron/crontabs
Option B (/var/spool/cron/crontabs) is correct because this directory stores per-user crontab files on Debian-based Linux systems, and attackers commonly plant scheduled jobs here to re-execute malware at recurring intervals for persistence. Option D (/etc/init.d) is correct because it holds SysV init scripts that start services at boot; malicious or modified scripts here can relaunch malware automatically on system startup. Option A (/proc) is a virtual, in-memory pseudo-filesystem exposing kernel and process state, not a persistent storage location where malware would be planted. Option C (/var/log/syslog) is a log file used for recording events and auditing, not a persistence mechanism. Option E (/etc/passwd) is the user account database; while it can be abused for account creation, it is not a standard malware persistence location in the sense of scheduled or boot-time execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/proc
Why it's wrong here
/proc is a virtual, in-memory filesystem exposing running process state; it vanishes on reboot and cannot hold a persistent artefact. It tempts because live process inspection reveals running malware, and /proc would be correct for examining currently executing processes, not for locating persistence across restarts.
- ✓
/var/spool/cron/crontabs
Why this is correct
Per-user cron jobs are stored as individual files under /var/spool/cron/crontabs, so attackers can schedule recurring malicious execution without touching the shared /etc/crontab. This satisfies the persistence requirement because these entries survive reboots and re-launch the payload.
- ✗
/var/log/syslog
Why it's wrong here
/var/log/syslog records system events and is volatile, so it evidences activity rather than the persistence mechanism itself; the question asks where malware establishes persistence. It tempts because logs are a standard forensic source, and syslog would be correct when investigating what a confirmed compromise did after execution.
- ✓
/etc/init.d
Why this is correct
/etc/init.d holds SysV init scripts that launch services at boot, so a malicious script placed there executes automatically on startup. This satisfies the persistence requirement because the service survives reboots and runs with the privileges assigned to its init configuration.
- ✗
/etc/passwd
Why it's wrong here
/etc/passwd stores local account definitions, not startup or scheduled execution; persistence requires a mechanism that reruns code, such as cron jobs or shell profiles. It tempts because attackers do add rogue accounts, but /etc/passwd would be correct when hunting unauthorised user accounts rather than persistence.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.