Courseiva
easyMultiple Select

200-201 Practice Question: Which two Sysmon Event IDs are most commonly…

Which two Sysmon Event IDs are most commonly associated with code injection techniques?

⚠ Common exam trap

Cisco often tests the distinction between direct indicators of injection (Event ID 8 and 10) versus indirect artifacts (Event ID 1 or 7), leading candidates to mistakenly choose process creation or image load events as primary injection indicators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Event ID 8 (CreateRemoteThread)

Event ID 8 (CreateRemoteThread) is correct because it is logged when a process creates a thread in another process, which is the classic Sysmon signature of remote thread injection (e.g., CreateRemoteThread or NtCreateThreadEx targeting a foreign process). Event ID 10 (ProcessAccess) is correct because it records a process opening a handle to another process, capturing the GrantedAccess mask (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) that injection techniques require to write shellcode and start execution in the target. Event ID 3 (Network connect) only logs outbound TCP/UDP connections and does not reflect in-memory injection behavior. Event ID 1 (Process creation) documents new process launches and may show a suspicious parent, but it does not capture cross-process memory or thread manipulation. Event ID 7 (Image loaded) records DLL/module loads and can hint at injected modules, yet it is not the primary indicator of the injection act itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event ID 3 (Network connect)

    Why it's wrong here

    Event ID 3 logs outbound TCP or UDP connections, so it shows command-and-control traffic after injection but never the injection itself. It is tempting because network connect events are the correct telemetry when tracing beaconing or exfiltration from an already-compromised host.

  • ✓

    Event ID 8 (CreateRemoteThread)

    Why this is correct

    Event ID 8 logs CreateRemoteThread, which fires when a process starts a thread inside another process. That cross-process thread creation is the classic Sysmon signature of remote code injection, directly matching the injection technique named in the stem.

  • ✗

    Event ID 1 (Process creation)

    Why it's wrong here

    Event ID 1 records process creation, capturing the image and command line of a new process, not the in-memory write into another process's address space that defines injection. It is tempting because process creation is the baseline for parent-child anomaly detection, which is the right telemetry for suspicious execution chains.

  • ✗

    Event ID 7 (Image loaded)

    Why it's wrong here

    Event ID 7 records images loaded into a process, which can hint at injected DLLs, but it is not one of the two IDs conventionally paired with code injection. It is tempting because image-load monitoring is the right telemetry for detecting unsigned or unexpected DLL sideloading in a process.

  • ✓

    Event ID 10 (ProcessAccess)

    Why this is correct

    Event ID 10 logs ProcessAccess, recording when one process opens a handle to another with rights such as memory write. Attackers need that handle to inject code, so this event captures the access step preceding injection.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.