Courseiva
Security Monitoring →hardMultiple Choice

200-201 Security Monitoring Practice Question

A SOC analyst is investigating a Windows workstation that has been exhibiting unusual outbound connections. Reviewing Sysmon Event ID 3 (Network Connection) logs, the analyst notices a process named svchost.exe with a parent process of cmd.exe initiating connections to an external IP on port 4444. On a healthy system, svchost.exe is normally spawned by services.exe. Which conclusion is most strongly supported by these log entries?

⚠ Common exam trap

The trap here is focusing on the process name svchost.exe as inherently benign, when the parent process and destination port are the discriminating evidence of compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Malware is masquerading as svchost.exe to blend in while communicating with a command-and-control server

The strongest conclusion is process masquerading for command-and-control. Legitimate svchost.exe always has services.exe as its parent, so a cmd.exe parent reveals either a renamed malicious executable or code injected into a spawned process. Combined with an outbound connection to port 4444, a well-known reverse-shell and C2 port, the analyst should treat the host as compromised and begin containment and forensic triage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A legitimate Windows service is making routine update connections

    Why it's wrong here

    Legitimate svchost.exe instances are launched by services.exe to host service DLLs, and their network activity aligns with known Windows services such as Windows Update. Here the parent is cmd.exe and the destination port is 4444, which does not match normal service behavior. The anomalous parent-child relationship and suspicious port strongly argue against a benign service connection.

  • ✗

    A scheduled task is running a legitimate administrative script

    Why it's wrong here

    Scheduled tasks typically launch via taskeng.exe or svchost.exe hosting the Task Scheduler service, not with cmd.exe as the parent of svchost.exe. Administrative scripts usually target internal management ports rather than an external IP on port 4444. The evidence points to adversary tradecraft rather than routine automation, so this benign explanation does not fit the observed telemetry.

  • ✓

    Malware is masquerading as svchost.exe to blend in while communicating with a command-and-control server

    Why this is correct

    Attackers commonly name malicious binaries svchost.exe or inject into the real process to evade casual inspection. The decisive evidence is the parent process: genuine svchost.exe is spawned by services.exe, so a cmd.exe parent indicates process masquerading or injection. The connection to port 4444, a frequent C2 and reverse-shell port, further supports malicious command-and-control activity requiring immediate investigation.

  • ✗

    The system is experiencing a memory corruption issue causing process misattribution

    Why it's wrong here

    Sysmon records process creation and network events from kernel callbacks, so parent process IDs are captured reliably at creation time. While PID reuse can occasionally confuse mapping, the combination of cmd.exe as parent and an outbound connection to port 4444 is a deliberate behavioral pattern, not a random corruption artifact. Memory corruption would not consistently produce this specific parent-child and port combination.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.