200-201 Host-Based Analysis Practice Question
A security analyst is investigating a Windows host for signs of fileless malware. The analyst runs a memory analysis tool and observes a process named 'powershell.exe' with a parent process of 'winword.exe'. The command line includes '-enc' followed by a long base64 string. Which technique is most likely being used by the attacker?
⚠ Common exam trap
The trap here is assuming that any PowerShell with encoded command is fileless malware, without considering the parent process, which in this case strongly indicates macro execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Malicious macro execution
The scenario describes winword.exe spawning powershell.exe with an encoded command, a hallmark of malicious macro execution. Attackers embed macros in Word documents that execute PowerShell to download or run payloads, often using base64 encoding to hide the script. Other techniques like DLL injection, process hollowing, or scheduled tasks do not match the observed parent-child relationship and command-line pattern, making macro execution the most likely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Malicious macro execution
Why this is correct
The parent process winword.exe spawning powershell.exe with an encoded command is a classic sign of a malicious Microsoft Word macro. Attackers use macros to execute PowerShell commands that download or run payloads, often encoding the command to evade detection. The '-enc' parameter indicates base64-encoded script, a common obfuscation method in macro-based attacks, making this the most likely technique.
- ✗
Process hollowing
Why it's wrong here
Process hollowing involves creating a legitimate process in a suspended state, replacing its memory with malicious code, and resuming it. This technique often results in a process with unexpected network connections or behavior, but the command line would typically reflect the original benign process, not an encoded PowerShell script. The presence of '-enc' with base64 suggests script-based execution, not hollowing.
- ✗
DLL injection
Why it's wrong here
DLL injection involves injecting malicious code into a legitimate process's memory space, often to evade detection. While it can be used for fileless attacks, the scenario describes a suspicious command line with an encoded PowerShell script spawned by Word, which is characteristic of macro-based execution rather than DLL injection. DLL injection would not typically manifest as a distinct powershell.exe process with an encoded command line.
- ✗
Scheduled task persistence
Why it's wrong here
Scheduled task persistence involves creating a task that runs malicious code at specific times or events. While PowerShell can be used in scheduled tasks, the scenario shows winword.exe as the parent, which is not typical for scheduled tasks (usually svchost.exe or taskeng.exe). The immediate execution from Word points to macro execution rather than a scheduled task, which would not have Word as the parent process.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.