Host-Based Analysis for Cisco CyberOps Associate (CBROPS 200-201)

This page covers the Host-Based Analysis domain of the Cisco CyberOps Associate (CBROPS 200-201) certification. Master Cybersecurity offers 31 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    What is the virtual address space for a Windows process?
    1. A. physical location of an object in memory
    2. B. set of pages that reside in the physical memory
    3. C. system-level memory protection feature built into the operating system
    4. D. set of virtual memory addresses that can be used
    Explanation

    The correct answer is: D. set of virtual memory addresses that can be used.

    When Windows creates a process it gives it a private virtual address space, meaning the set of virtual memory addresses that process is allowed to use. The memory manager translates those virtual addresses to physical page frames through per-process page tables, so two processes can each reference the same virtual address and land on completely different physical memory, and neither can reach into the other's allocations without an explicit shared-memory or debugging interface. That isolation is why an analyst must dump one specific process to recover its strings, injected code, or decrypted payloads. The physical location of an object in memory is a physical address, the far side of the translation, not the address space itself. The set of pages actually resident in RAM is the working set, a shifting subset of the address space as pages are trimmed and faulted back in. A system-level memory protection feature describes mitigations such as data execution prevention or address space layout randomisation, which harden how the space is used rather than define what it is.

  2. Question 2

    Refer to the exhibit. An engineer is analyzing this Cuckoo Sandbox report for a PDF file that has been downloaded from an email. What is the state of this file?
    1. A. The file has an embedded executable and was matched by PEiD threat signatures for further analysis.
    2. B. The file has an embedded non-Windows executable but no suspicious features are identified.
    3. C. The file has an embedded Windows 32 executable and the Yara field lists suspicious features for further analysis.
    4. D. The file was matched by PEiD threat signatures but no suspicious features are identified since the signature list is up to date.
    Explanation

    The correct answer is: C. The file has an embedded Windows 32 executable and the Yara field lists suspicious features for further analysis..

    Two separate areas of a Cuckoo report answer this question about a document sample. The static analysis area reports what the file actually contains, and an embedded PE32 image inside a PDF is a Windows 32-bit executable carried within the document, which is a strong sign of a weaponized attachment because a legitimate PDF has no reason to ship a Windows binary. The signature area is where Yara rule matches appear, and those hits enumerate the suspicious features an analyst should pursue, so the correct reading is an embedded Windows 32-bit executable together with Yara findings that warrant further analysis. PEiD works differently: it matches packer and compiler signatures against a PE file, its database is narrow and long unmaintained, and it very often matches nothing, so it is not what produced these findings. An embedded non-Windows executable with nothing suspicious contradicts a PE32 identification, and treating an up-to-date signature list as proof of innocence inverts the logic, since a clean packer check never clears a file that has Yara matches against it.

  3. Question 3

    Which two components reduce the attack surface on an endpoint? (Choose two.)
    1. A. secure boot
    2. B. load balancing
    3. C. increased audit log levels
    4. D. restricting USB ports
    5. E. full packet captures at the endpoint
    Explanation

    The correct answers are: A. secure boot, D. restricting USB ports.

    Attack surface is the set of ways an attacker can reach or influence an endpoint, so a control shrinks it only by removing an entry point or an execution path. Secure boot has the firmware verify the digital signature of each component in the boot chain before handing control onward, which eliminates bootkits, rootkits, and tampered loaders as a route to persistence below the operating system. Restricting USB ports removes the physical delivery path used by malicious removable media, rogue human interface devices, and unauthorized data exfiltration, closing an avenue that needs no network access at all. Load balancing distributes traffic across servers for availability and performance; it changes nothing about what an individual endpoint exposes and can even add reachable nodes. Raising audit log levels increases what can be reconstructed after the fact, improving detection and investigation while leaving every existing entry point as reachable as before. Full packet capture at the endpoint is likewise a visibility measure, and it adds a new store of sensitive data to protect.

  4. Question 4

    Refer to the exhibit. Which event is occurring?
    1. A. A binary named "submit" is running on VM cuckoo1.
    2. B. A binary is being submitted to run on VM cuckoo1
    3. C. A binary on VM cuckoo1 is being submitted for evaluation
    4. D. A URL is being evaluated to see if it has a malicious binary
    Explanation

    The correct answer is: C. A binary on VM cuckoo1 is being submitted for evaluation.

    Cuckoo is a dynamic malware analysis platform: a sample is handed to it, executed inside an isolated guest virtual machine, and every behavior it produces is recorded so the sample can be judged. The activity here is therefore a binary tied to the guest machine named cuckoo1 being submitted for evaluation, meaning it is queued for behavioral analysis rather than launched for ordinary use. Reading submit as the name of a file mistakes the verb of the workflow for a filename; the word describes what is being done with the sample, not what the sample is called. Describing it only as a binary being submitted to run on the guest stops short of the point, because a sandbox never runs a sample for its own sake, the execution exists to produce an evaluation report covering registry writes, dropped files, process injection, and contacted domains and addresses. A URL being checked for a malicious binary describes the separate URL analysis mode, where the submitted object is a link rather than a file, which does not apply when the object under analysis is itself an executable.

  5. Question 5

    Refer to the exhibit. In which Linux log file is this output found?
    1. A. /var/log/authorization.log
    2. B. /var/log/dmesg
    3. C. var/log/var.log
    4. D. /var/log/auth.log
    Explanation

    The correct answer is: D. /var/log/auth.log.

    On Debian and Ubuntu systems, authentication activity is written to /var/log/auth.log: sshd accepted and failed password lines, sudo invocations along with the commands run, su attempts, PAM session opens and closes, and account changes made by useradd or passwd. That file is the first place to look when tracing who logged in, from where, and whether privilege escalation followed, and on Red Hat family distributions the equivalent content lands in /var/log/secure. There is no /var/log/authorization.log in any standard distribution, so that path can be discarded immediately as invented. The dmesg file holds a capture of the kernel ring buffer, meaning device detection, driver messages, and hardware errors, and it carries no user authentication records at all. The path var/log/var.log is not a real log file, and it is written without a leading slash, so it is not even an absolute path. General service and system messages that are not authentication related go to /var/log/messages or /var/log/syslog rather than to the authentication log.

Other Cisco CyberOps Associate (CBROPS 200-201) domains

Practice all 31 Host-Based Analysis questions · Browse Cisco CyberOps Associate (CBROPS 200-201)