Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisEasy

A security analyst is investigating a Windows workstation that is exhibiting unusual network activity and process behavior. The analyst suspects a sophisticated malware infection. Which of the following host-based tools is best suited for identifying hidden processes, kernel-mode rootkits, and injected code on a live Windows system?

  1. ASysinternals Process Explorer
  2. Bnetstat
  3. CEvent Viewer
  4. Dtasklist
Show answer & explanation

Correct answer: A. Sysinternals Process Explorer

Sysinternals Process Explorer is a powerful tool for Windows that provides detailed information about running processes, including parent-child relationships, loaded modules, and can identify hidden processes or those with injected code. It offers more depth than basic command-line tools for advanced malware analysis.

Why the other options are wrong

  • B. netstat is used for displaying active network connections, not for identifying hidden processes or kernel-mode rootkits.
  • C. Event Viewer collects system logs but does not directly identify hidden processes or kernel-mode rootkits in real-time.
  • D. tasklist lists running processes but lacks the deep inspection capabilities needed to detect hidden or injected code.

Sysinternals Process Explorer

A free utility from Microsoft that provides advanced process management and analysis capabilities for Windows operating systems.

  • Displays hierarchical process tree
  • Shows loaded DLLs and handles
  • Can identify hidden or injected code

Memory trick: Process Explorer is your magnifying glass for Windows processes.

More Host-Based Analysis questions