Courseiva
mediumMultiple Choice

200-201 Practice Question: During a host-based investigation, an analyst…

During a host-based investigation, an analyst finds a process named 'svchost.exe' consuming high CPU. The process path is 'C:\Windows\Temp\svchost.exe'. What should the analyst conclude?

⚠ Common exam trap

Cisco often tests the misconception that any process named 'svchost.exe' is automatically legitimate, but the trap here is that the file path is the critical differentiator—malware frequently uses the same name as a trusted system binary but runs from an unauthorized location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It is likely malware disguised as a legitimate process

The legitimate svchost.exe (Service Host) runs from C:\Windows\System32, not C:\Windows\Temp. The Temp directory is a common location for malware to masquerade as system processes to evade detection. High CPU usage combined with an anomalous path strongly indicates malicious activity, as legitimate svchost.exe instances are signed by Microsoft and reside in System32.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It is a legitimate Windows service host process

    Why it's wrong here

    Legitimate svchost.exe executes solely from %SystemRoot%\System32; a copy in C:\Windows\Temp is a masquerading binary. The conclusion is tempting because the filename matches the genuine service host, but path is the deciding artefact, and high CPU from Temp indicates malicious execution.

  • ✗

    It is a third-party application that requires investigation

    Why it's wrong here

    Third-party applications normally install under Program Files or a vendor directory, not Windows\Temp, and legitimate svchost.exe runs only from System32. The label is tempting because unusual binaries can be third-party software, but the Temp path plus masqueraded name indicates process injection or malware.

  • ✓

    It is likely malware disguised as a legitimate process

    Why this is correct

    Legitimate svchost.exe instances always reside in C:\Windows\System32 and are launched by services.exe; a copy running from C:\Windows\Temp violates that invariant, indicating masquerading malware. The anomalous path, combined with sustained high CPU, satisfies the stem's evidence of process impersonation rather than normal service-host behaviour.

  • ✗

    It is a temporary file created by Windows Update

    Why it's wrong here

    Windows Update stages files under SoftwareDistribution\Download, not as an executable named svchost.exe in Windows\Temp, and update files are not running processes. The explanation is tempting because Temp holds transient installer data, but the observed process is a masqueraded binary executing from a non-standard path.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.