Courseiva
Host-Based Analysis →hardMultiple Choice

200-201 Host-Based Analysis Practice Question

A security analyst is investigating a Windows host for signs of fileless malware. The analyst runs a memory analysis tool and observes a process named 'powershell.exe' with a parent process of 'winword.exe'. The command line includes '-enc' followed by a long base64 string. Which technique is most likely being used by the attacker?

⚠ Common exam trap

The trap here is assuming that any PowerShell with encoded command is fileless malware, without considering the parent process, which in this case strongly indicates macro execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Malicious macro execution

The scenario describes winword.exe spawning powershell.exe with an encoded command, a hallmark of malicious macro execution. Attackers embed macros in Word documents that execute PowerShell to download or run payloads, often using base64 encoding to hide the script. Other techniques like DLL injection, process hollowing, or scheduled tasks do not match the observed parent-child relationship and command-line pattern, making macro execution the most likely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Malicious macro execution

    Why this is correct

    The parent process winword.exe spawning powershell.exe with an encoded command is a classic sign of a malicious Microsoft Word macro. Attackers use macros to execute PowerShell commands that download or run payloads, often encoding the command to evade detection. The '-enc' parameter indicates base64-encoded script, a common obfuscation method in macro-based attacks, making this the most likely technique.

  • ✗

    Process hollowing

    Why it's wrong here

    Process hollowing involves creating a legitimate process in a suspended state, replacing its memory with malicious code, and resuming it. This technique often results in a process with unexpected network connections or behavior, but the command line would typically reflect the original benign process, not an encoded PowerShell script. The presence of '-enc' with base64 suggests script-based execution, not hollowing.

  • ✗

    DLL injection

    Why it's wrong here

    DLL injection involves injecting malicious code into a legitimate process's memory space, often to evade detection. While it can be used for fileless attacks, the scenario describes a suspicious command line with an encoded PowerShell script spawned by Word, which is characteristic of macro-based execution rather than DLL injection. DLL injection would not typically manifest as a distinct powershell.exe process with an encoded command line.

  • ✗

    Scheduled task persistence

    Why it's wrong here

    Scheduled task persistence involves creating a task that runs malicious code at specific times or events. While PowerShell can be used in scheduled tasks, the scenario shows winword.exe as the parent, which is not typical for scheduled tasks (usually svchost.exe or taskeng.exe). The immediate execution from Word points to macro execution rather than a scheduled task, which would not have Word as the parent process.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.