TechNuggets Academy

Host-Based Analysis

Free Cisco Certified CyberOps Associate practice — 6 questions on Host-Based Analysis, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Host-Based Analysis
A forensic analyst uses a hardware write blocker to acquire a bit-for-bit image of a suspect's hard drive and computes a SHA-256 hash of both the source drive and the resulting image immediately after acquisition. Three weeks later, prior to presenting findings, the analyst recalculates the hash of the stored image file and it matches the value recorded in the original case documentation. What does this MOST likely indicate?
A matching hash value calculated at two different points in time proves the bit-level content of the image file has not changed, which is the standard method for demonstrating an untampered (forensically sound) copy of evidence.
Question 2 of 6 · Host-Based Analysis
A SOC analyst is investigating a Windows 10 endpoint to determine whether a specific suspicious executable was run, how many times it executed, and approximately when it was last run. Which artifact provides this information most directly?
Windows Prefetch files (.pf) are created to speed up application launches and store the executable name, last-run timestamp(s), and a run counter, making them a primary artifact for proving execution frequency and timing.
Question 3 of 6 · Host-Based Analysis
An analyst is reviewing logs on an Ubuntu 22.04 Linux server to identify failed SSH login attempts associated with a suspected brute-force attack. Which log file should be examined first?
On Debian-based distributions such as Ubuntu, authentication-related events including SSH login successes and failures are logged to /var/log/auth.log by the PAM subsystem.
Question 4 of 6 · Host-Based Analysis
During an incident response engagement, an analyst physically hands a seized hard drive to a second investigator for further analysis, but neither analyst records who received the evidence, the date and time of transfer, or the reason for the handoff. What has been compromised as a result?
Chain of custody requires a documented, unbroken record of who possessed evidence, when transfers occurred, and why, so that its integrity can be legally established; an undocumented handoff directly breaks this chain.
Question 5 of 6 · Host-Based Analysis
A SOC team receives a suspicious executable attached to a phishing email and wants to observe its file system modifications, registry changes, and outbound network connection attempts without exposing the production network to risk. Which endpoint technology is BEST suited for this task?
Sandboxing is designed specifically to safely detonate unknown or suspicious files in an isolated environment while capturing detailed behavioral telemetry such as file, registry, and network activity, which is exactly the goal described.
Question 6 of 6 · Host-Based Analysis
An analyst discovers that a specific file hash on a compromised host matches a hash previously associated with a known ransomware family in a threat intelligence feed. In CyberOps terminology, this static artifact is best classified as which of the following?
A file hash is a static, after-the-fact forensic artifact that confirms a compromise occurred, which is the defining characteristic of an Indicator of Compromise (IOC), as opposed to a behavioral pattern observed during an active attack.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →