Courseiva
Host-Based Analysis →easyMultiple Select

200-201 Host-Based Analysis Practice Question

A Windows analyst uses Process Explorer to investigate parent-child relationships. Which TWO characteristics are commonly associated with malicious processes?

⚠ Common exam trap

200-201 often tests the ability to distinguish benign from malicious process characteristics. Candidates may be misled by options that sound suspicious but are actually normal (e.g., signed parent process) or by unusual but not definitively malicious chains (svchost.exe to explorer.exe). The key is to focus on well-known malicious indicators like Temp folder execution and document readers spawning shells.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A process running from a user's Temp folder with a random name

Option B is correct because malware frequently drops and executes its payload from user-writable directories such as %TEMP% (e.g., C:\Users\<user>\AppData\Local\Temp) using randomized file names to evade signature-based detection and blend into transient files. Option E is correct because a document reader like winword.exe spawning a command interpreter such as cmd.exe (or powershell.exe) is a classic indicator of a malicious macro or exploit performing code execution, since legitimate Word usage does not normally launch shells. Option A is not suspicious by itself, as validly signed parent processes are typical of legitimate software and signatures indicate trustworthiness rather than malice. Option C describes benign behavior, since long uptime with low CPU is normal for many background services. Option D is also not inherently malicious, because svchost.exe spawning explorer.exe can occur in legitimate scenarios and is not a standard malware parent-child pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A parent process with a valid digital signature

    Why it's wrong here

    A valid digital signature indicates a legitimately signed binary, which is a benign indicator rather than a malicious characteristic; attackers often use unsigned or stolen-certificate binaries. It is tempting because signature checks are part of triage, but a valid signature alone neither confirms nor suggests compromise.

  • ✓

    A process running from a user's Temp folder with a random name

    Why this is correct

    Processes executing from a user's Temp directory with randomised filenames evade signature-based detection and are atypical of legitimate software, which installs to Program Files or AppData. This masquerading behaviour satisfies the stem's request for a malicious parent-child indicator.

  • ✗

    A process with a long uptime and low CPU usage

    Why it's wrong here

    Long uptime with low CPU usage describes a stable, idle legitimate process such as a service; malicious processes more often show short lifetimes, high CPU, or unusual network activity. It is tempting because persistence mechanisms do run quietly, but these metrics alone are not a recognised malicious indicator.

  • ✗

    A process chain where the parent is svchost.exe and child is explorer.exe

    Why it's wrong here

    svchost.exe spawning explorer.exe inverts the normal relationship: explorer.exe is the user shell and typically launches svchost-hosted services indirectly, so this chain suggests injection or masquerading. It is tempting because svchost.exe is a legitimate host process, but its presence as a parent of explorer.exe is the anomaly.

  • ✓

    A child process spawned by a document reader (e.g., winword.exe spawning cmd.exe)

    Why this is correct

    A document reader spawning a command shell is anomalous because winword.exe should not create cmd.exe; this parent-child mismatch satisfies the question's malicious-process indicator. Legitimate Word sessions launch Office subprocesses, not shells, so this behaviour signals exploitation, such as a malicious macro executing code.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.