200-201 Host-Based Analysis Practice Question
An analyst runs Volatility's pstree plugin on a memory dump. The output shows that a process 'svchost.exe' is the child of 'explorer.exe'. What is suspicious about this?
⚠ Common exam trap
Cisco often tests the misconception that svchost.exe can be a child of any process because it is a common system process, but the trap is that candidates forget the strict parent-child relationship enforced by the Service Control Manager in Windows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
svchost.exe should be a child of services.exe, not explorer.exe
In a normal Windows system, svchost.exe is a service host process that should always be a child of services.exe, which is the Service Control Manager (SCM). When svchost.exe appears as a child of explorer.exe, it indicates that a malicious process or attacker has spawned a fake svchost.exe from explorer.exe to evade detection, as legitimate svchost.exe instances are never launched from the Windows shell.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
explorer.exe should not have any child processes
Why it's wrong here
The parent–child relationship itself is the anomaly: svchost.exe should be spawned by services.exe, not explorer.exe, indicating process injection or masquerading. The claim that explorer.exe has no children is false — it routinely spawns user applications. This option would fit only if the stem showed explorer.exe with no child processes at all.
- ✗
Nothing, svchost.exe can be a child of any process
Why it's wrong here
explorer.exe is a user-mode process and never spawns svchost.exe, which is launched by services.exe, so this parent-child relationship indicates process injection or masquerading. It is tempting because svchost.exe legitimately hosts many services, and it would be correct to dismiss the finding if the parent were services.exe.
- ✓
svchost.exe should be a child of services.exe, not explorer.exe
Why this is correct
Legitimate svchost.exe instances are spawned by services.exe, which hosts service DLLs. A parent of explorer.exe indicates process injection or masquerading, since explorer.exe never launches service hosts. This parent-child anomaly is the specific indicator the analyst must flag.
- ✗
The pstree output is unreliable
Why it's wrong here
Volatility's pstree reconstructs parent-child links from pool-tagged process structures and is reliable on intact memory images. Dismissing the output evades the real finding: svchost.exe parented by explorer.exe rather than services.exe signals masquerading, though pstree can misreport when structures are corrupted.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.