easyMultiple Choice
Windows Registry Persistence: Services and Run Keys
Which Windows registry hive is most likely to contain evidence of malware persistence via a service?
Quick Answer
The answer is HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, as this registry hive stores the configuration for all Windows services, including their executable paths and startup types. Malware often installs itself as a service to achieve persistence, and evidence of this can be found by examining the ImagePath value under a suspicious service subkey. This is the correct location for service-based persistence, unlike the Run keys which handle startup programs for users. On the Cisco CyberOps Associate 200-201 exam, this tests your ability to distinguish between persistence mechanisms—a common trap is confusing the Run keys (user-level startup) with the Services hive (system-level service persistence). Remember: services run before user login, so malware hiding here survives reboots silently. A helpful memory tip is “Services start silently, Run keys run visibly”—if the persistence is automatic and system-wide, check the Services hive first.
⚠ Common exam trap
Cisco often tests the distinction between Run keys (user logon persistence) and Services keys (system service persistence), and the trap here is that candidates confuse the Run keys with service persistence because both are common persistence mechanisms, but only the Services hive stores service-specific configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
The HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services registry hive stores the configuration for all Windows services, including their executable paths and startup types. Malware often installs itself as a service to achieve persistence, and evidence of this can be found by examining the ImagePath value under a suspicious service subkey. This is the correct location for service-based persistence, unlike the Run keys which handle startup programs for users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
HKLM\...\Run records machine-wide logon autostart programs, not services; service persistence lives under HKLM\SYSTEM\CurrentControlSet\Services. It is tempting because HKLM Run is machine-wide and frequently abused, and it would be correct for identifying autostart entries rather than service installation.
- ✓
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Why this is correct
Services configured for persistence are recorded under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, where each subkey holds the service's ImagePath, Start type and parameters. This satisfies the stem's requirement for the registry hive most likely to evidence service-based malware persistence, since the SYSTEM hive stores all service definitions.
- ✗
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Why it's wrong here
HKCU\...\Run holds per-user logon autostart entries, not service registrations, so service-based persistence would not appear there. It is tempting because Run keys are a common autostart location, and they would be the right hive for user-level logon persistence.
- ✗
HKEY_LOCAL_MACHINE\SAM
Why it's wrong here
The SAM hive stores local account and group definitions, not service configuration, so service persistence evidence is absent. It is tempting because SAM is examined for account creation and privilege changes, and it would be the right hive when investigating rogue local users rather than malicious services.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 200-201
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which Windows registry hive contains user-specific configuration settings that can be modified by applications?
easy- A.HKEY_CLASSES_ROOT
- B.HKEY_LOCAL_MACHINE
- ✓ C.HKEY_CURRENT_USER
- D.HKEY_USERS
Why C: HKEY_CURRENT_USER (HKCU) is the correct answer because it stores user-specific configuration settings, such as desktop preferences, environment variables, and application settings, that are loaded from the NTUSER.DAT file when a user logs in. Applications modify this hive to persist per-user customizations, making it the primary location for user-level registry changes.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.