Courseiva
hardMultiple Choice

200-201 Practice Question: Based on the exhibit, what does the sequence of…

Exhibit

Refer to the exhibit.

Event 4688 (Process Creation):
New Process ID: 0x1234
New Process Name: C:\Users\Public\svchost.exe
Creator Process ID: 0x9ABC
Creator Process Name: C:\Windows\System32\wmiprvse.exe
Process Command Line: svchost.exe -k ntsvcs

Event 4688 (Process Creation):
New Process ID: 0x5678
New Process Name: C:\Windows\System32\svchost.exe
Creator Process ID: 0x1234
Creator Process Name: C:\Users\Public\svchost.exe
Process Command Line: C:\Windows\System32\calc.exe

Based on the exhibit, what does the sequence of events indicate?

⚠ Common exam trap

Cisco often tests the misconception that svchost.exe is always legitimate and that wmiprvse.exe only spawns itself or system processes, when in fact attackers can use WMI to launch arbitrary executables with a misleading name.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A process masquerading as svchost.exe was spawned by wmiprvse.exe (likely via WMI), and then that malicious process launched calc.exe, a suspicious behavior.

The exhibit shows wmiprvse.exe (the WMI Provider Host) spawning svchost.exe, which then launches calc.exe. In normal operations, wmiprvse.exe does not spawn svchost.exe; svchost.exe is a generic host process for Windows services and is typically launched by services.exe. The sequence indicates process masquerading: an attacker used WMI to execute a malicious binary named svchost.exe, which then launched calc.exe as a suspicious payload. This is a classic indicator of lateral movement or privilege escalation via WMI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The wmiprvse.exe process is known to spawn svchost.exe for system health checks.

    Why it's wrong here

    wmiprvse.exe spawning svchost.exe is not a documented health-check behaviour; svchost.exe is loaded by services.exe to host service DLLs. The claim tempts because WMI performs legitimate system queries, so analysts may dismiss the chain as benign, yet the parent-child relationship itself violates normal Windows process lineage.

  • ✓

    A process masquerading as svchost.exe was spawned by wmiprvse.exe (likely via WMI), and then that malicious process launched calc.exe, a suspicious behavior.

    Why this is correct

    The parent-child sequence shows wmiprvse.exe spawning a process named svchost.exe, which is anomalous because the genuine svchost.exe is launched by services.exe. That masquerading process then spawning calc.exe confirms malicious WMI-based execution rather than legitimate system activity.

  • ✗

    The user is executing a macro that opens Calculator.

    Why it's wrong here

    A macro opening Calculator would show a document application (WINWORD.EXE) spawning calc.exe, not wmiprvse.exe spawning svchost.exe then calc.exe. Macro execution is tempting because Office macros commonly launch child processes, and that pattern would fit a malicious document scenario rather than this WMI-based chain.

  • ✗

    A legitimate system process (wmiprvse.exe) launched a service host, which then launched calc.exe for maintenance.

    Why it's wrong here

    Legitimate wmiprvse.exe does not spawn svchost.exe, which is a service container launched by services.exe; the exhibit's parent-child chain is anomalous, indicating process injection or lateral tooling. The option tempts because WMI is genuinely used for maintenance, but that activity originates from WMI providers, not svchost.exe spawning calc.exe.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.