Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard

A security analyst is investigating an alert from an endpoint protection platform (EPP) indicating a suspicious PowerShell script executed on a Windows server. The EPP reported that the script attempted to disable Windows Defender and establish a persistent network connection. To understand the full scope of the script's actions and potential impact, which host-based artifact would provide the most comprehensive detail about the script's execution, including its arguments, execution path, and any child processes it spawned?

  1. APowerShell Operational Log
  2. BRegistry hives
  3. CWindows Event Log - System
  4. DWindows Event Log - Security
Show answer & explanation

Correct answer: A. PowerShell Operational Log

The PowerShell Operational Log (Microsoft-Windows-PowerShell/Operational) provides highly detailed information about PowerShell script execution, including the full script block, arguments, execution policy changes, and any commands run, which is crucial for understanding malicious PowerShell activity.

Why the other options are wrong

  • B. Registry hives store configuration data but do not log the dynamic execution details of scripts or their arguments.
  • C. System logs record system-level events and errors, not detailed application-specific execution information like PowerShell scripts.
  • D. Security logs record authentication, authorization, and some process creation events, but lack the granular detail of PowerShell script content and arguments.

PowerShell Operational Log

A specific Windows Event Log channel (`Microsoft-Windows-PowerShell/Operational`) that records detailed activities of the PowerShell engine, including script block logging.

  • Records full script content and arguments.
  • Crucial for detecting and analyzing PowerShell-based attacks.
  • Requires specific configuration for full script block logging.

Memory trick: When PowerShell goes rogue, look directly at its 'operational' journal, not just the general 'security' or 'system' diaries.

More Host-Based Analysis questions