Courseiva
Host-Based Analysis →hardMultiple Choice

200-201 Host-Based Analysis Practice Question

An analyst is examining a Windows 10 host and discovers that a service named 'WinDefendSvc' is registered with a binary path of C:\ProgramData\svchost.exe and a display name of 'Windows Defender Service'. The legitimate Windows Defender service uses a different name and binary path. Which conclusion is most accurate?

⚠ Common exam trap

The trap here is trusting a service because its name resembles a known Microsoft component, without verifying the actual binary path and digital signature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

This indicates a masquerading attempt, because the service name mimics Windows Defender while its binary is placed in a user-writable directory, which is typical of malware persistence.

Legitimate Windows Defender registers as the WinDefend service with its binary under C:\Program Files\Windows Defender. A service named WinDefendSvc pointing to C:\ProgramData\svchost.exe combines two red flags: a typosquatted name impersonating a security product and a binary in a user-writable directory. This pattern is characteristic of masquerading persistence, and the analyst should investigate the binary, its signature, and its network activity rather than dismissing it as legitimate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The service is a leftover from a Windows Update that failed to clean up and can be safely ignored, since the binary is named svchost.exe.

    Why it's wrong here

    The filename svchost.exe is not sufficient to declare a binary legitimate, because malware commonly names itself svchost.exe to blend in. A legitimate svchost.exe resides in C:\Windows\System32 and is invoked by services.exe with specific -k parameters. A copy in C:\ProgramData with a typosquatted service name is not a cleanup artifact and should be investigated as potential malware.

  • ✗

    This is a benign third-party antivirus service that has registered itself under a Microsoft-like name to be trusted by the operating system.

    Why it's wrong here

    Legitimate third-party antivirus products register under their own vendor names, not names that impersonate Microsoft Defender. They also install binaries under Program Files with signed executables, not in ProgramData. A service that deliberately mimics a Microsoft name and uses a user-writable path is not behaving like a legitimate security product and should be considered suspicious.

  • ✗

    This is a legitimate alternate Windows Defender service name used on some Windows 10 builds and should be verified with Get-Service before further action.

    Why it's wrong here

    Windows Defender's real service is WinDefend with a binary in C:\Program Files\Windows Defender. Microsoft does not register an alternate service named WinDefendSvc running from C:\ProgramData. The typosquatted name and the user-writable path are strong indicators of malicious masquerading. Verifying with Get-Service would simply confirm the suspicious service exists, not legitimize it.

  • ✓

    This indicates a masquerading attempt, because the service name mimics Windows Defender while its binary is placed in a user-writable directory, which is typical of malware persistence.

    Why this is correct

    C:\ProgramData is writable by standard users, unlike system directories, making it a common staging ground for malicious binaries. The service name 'WinDefendSvc' closely mimics the legitimate 'WinDefend' to evade casual inspection. Combined with the non-standard binary path, this is a classic masquerading persistence technique. The analyst should treat it as malicious and investigate the binary and its network behavior.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.