hardMultiple Choice
200-201 Practice Question: Based on the exhibit, what does the sequence of…
Exhibit
Refer to the exhibit. Event 4688 (Process Creation): New Process ID: 0x1234 New Process Name: C:\Users\Public\svchost.exe Creator Process ID: 0x9ABC Creator Process Name: C:\Windows\System32\wmiprvse.exe Process Command Line: svchost.exe -k ntsvcs Event 4688 (Process Creation): New Process ID: 0x5678 New Process Name: C:\Windows\System32\svchost.exe Creator Process ID: 0x1234 Creator Process Name: C:\Users\Public\svchost.exe Process Command Line: C:\Windows\System32\calc.exe
Based on the exhibit, what does the sequence of events indicate?
⚠ Common exam trap
Cisco often tests the misconception that svchost.exe is always legitimate and that wmiprvse.exe only spawns itself or system processes, when in fact attackers can use WMI to launch arbitrary executables with a misleading name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A process masquerading as svchost.exe was spawned by wmiprvse.exe (likely via WMI), and then that malicious process launched calc.exe, a suspicious behavior.
The exhibit shows wmiprvse.exe (the WMI Provider Host) spawning svchost.exe, which then launches calc.exe. In normal operations, wmiprvse.exe does not spawn svchost.exe; svchost.exe is a generic host process for Windows services and is typically launched by services.exe. The sequence indicates process masquerading: an attacker used WMI to execute a malicious binary named svchost.exe, which then launched calc.exe as a suspicious payload. This is a classic indicator of lateral movement or privilege escalation via WMI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The wmiprvse.exe process is known to spawn svchost.exe for system health checks.
Why it's wrong here
wmiprvse.exe spawning svchost.exe is not a documented health-check behaviour; svchost.exe is loaded by services.exe to host service DLLs. The claim tempts because WMI performs legitimate system queries, so analysts may dismiss the chain as benign, yet the parent-child relationship itself violates normal Windows process lineage.
- ✓
A process masquerading as svchost.exe was spawned by wmiprvse.exe (likely via WMI), and then that malicious process launched calc.exe, a suspicious behavior.
Why this is correct
The parent-child sequence shows wmiprvse.exe spawning a process named svchost.exe, which is anomalous because the genuine svchost.exe is launched by services.exe. That masquerading process then spawning calc.exe confirms malicious WMI-based execution rather than legitimate system activity.
- ✗
The user is executing a macro that opens Calculator.
Why it's wrong here
A macro opening Calculator would show a document application (WINWORD.EXE) spawning calc.exe, not wmiprvse.exe spawning svchost.exe then calc.exe. Macro execution is tempting because Office macros commonly launch child processes, and that pattern would fit a malicious document scenario rather than this WMI-based chain.
- ✗
A legitimate system process (wmiprvse.exe) launched a service host, which then launched calc.exe for maintenance.
Why it's wrong here
Legitimate wmiprvse.exe does not spawn svchost.exe, which is a service container launched by services.exe; the exhibit's parent-child chain is anomalous, indicating process injection or lateral tooling. The option tempts because WMI is genuinely used for maintenance, but that activity originates from WMI providers, not svchost.exe spawning calc.exe.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.