Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 Practice Question: An analyst is investigating a host that is…

An analyst is investigating a host that is suspected of being compromised. She runs the 'netstat -anb' command and sees an established connection to an unknown IP address on port 4444. The associated process is svchost.exe. Which conclusion is MOST appropriate?

⚠ Common exam trap

Cisco often tests the misconception that svchost.exe never makes outbound connections, when in fact many Windows services (e.g., BITS, Windows Update) do; the trap is assuming any outbound connection from a critical process is automatically legitimate or automatically malicious without considering the port and context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The host may be infected with malware that is injecting code into svchost.exe.

Svchost.exe is a legitimate Windows service host process, but it is a common target for malware that uses process injection or DLL sideloading to hide malicious network activity. The established connection to an unknown IP on port 4444 (often associated with Metasploit or backdoor listeners) indicates the process may be hosting injected code, not that svchost.exe itself is inherently malicious. The analyst should investigate further before concluding compromise or taking action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The host is definitely compromised because svchost.exe should not make outbound connections.

    Why it's wrong here

    svchost.exe does make outbound connections for legitimate services like Windows Update.

  • The host may be infected with malware that is injecting code into svchost.exe.

    Why this is correct

    Malware often injects into svchost.exe to hide its network activity.

  • The analyst should immediately kill the svchost.exe process.

    Why it's wrong here

    Killing svchost.exe could cause system instability and destroy evidence.

  • The connection is legitimate because svchost.exe is a critical Windows process.

    Why it's wrong here

    The unknown IP and non-standard port suggest the connection is not legitimate.

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.