200-201 Host-Based Analysis Practice Question
A security analyst is reviewing a Windows 10 endpoint that is suspected of being compromised. The analyst opens Task Manager and notices a process named 'lsass.exe' running with a PID of 1234, but its parent process is 'cmd.exe' rather than 'wininit.exe'. The analyst also observes that the process path is 'C:\Users\Public\lsass.exe'. Which type of attack is most likely indicated by these findings?
⚠ Common exam trap
The trap here is assuming that any process with a legitimate name is safe, but the path and parent process are critical for verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Process masquerading
The genuine lsass.exe runs from C:\Windows\System32 and is spawned by wininit.exe. A process named lsass.exe running from C:\Users\Public with cmd.exe as its parent is a strong indicator of process masquerading, where malware mimics a legitimate process name to evade detection. This technique is commonly used by attackers to blend in with normal system activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rootkit infection
Why it's wrong here
Rootkits typically hide processes, files, and registry keys, making them difficult to detect via Task Manager. The fact that the anomalous process is visible suggests it is not a rootkit. While rootkits can cause process anomalies, the specific indicators of wrong parent and path are more characteristic of masquerading.
- ✗
Process hollowing
Why it's wrong here
Process hollowing typically involves creating a legitimate process in a suspended state, replacing its memory with malicious code, and resuming it. In this scenario, the legitimate process would still appear with its original parent and path, not an anomalous parent and path. The indicators here point to a masquerading executable rather than hollowing.
- ✓
Process masquerading
Why this is correct
Process masquerading occurs when malware names its executable after a legitimate system process, such as lsass.exe, but runs from an unusual location and with an unexpected parent. Here, the path 'C:\Users\Public\lsass.exe' and parent 'cmd.exe' are clear indicators that this is a fake lsass.exe, not the genuine one that runs from System32 and is spawned by wininit.exe.
- ✗
DLL injection
Why it's wrong here
DLL injection involves injecting a malicious DLL into a legitimate process, which would not change the parent process or the executable path of the host process. The observed anomalies—wrong parent and non-standard path—are not typical of DLL injection, which would require memory analysis to detect.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.