Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A user reports that while working on a spreadsheet, the Windows 10 workstation suddenly displays a User Account Control (UAC) prompt requesting permission for an application named 'svch0st.exe' to make changes. The user did not launch any application. Which of the following is the MOST likely scenario?

⚠ Common exam trap

The trap here is that candidates may recognize 'svchost.exe' as a legitimate Windows process and assume the prompt is benign, overlooking the deliberate misspelling (zero instead of 'o') which is a clear indicator of malware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Malware is attempting to escalate privileges.

The UAC prompt for 'svch0st.exe' is suspicious because the legitimate Windows service host process is named 'svchost.exe', not 'svch0st.exe' (with a zero replacing the letter 'o'). This typo-squatting technique is commonly used by malware to masquerade as a trusted system process. Since the user did not initiate any action, the most likely scenario is that malware is attempting to escalate privileges via UAC bypass to gain administrative access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A legitimate Windows service is requesting an update.

    Why it's wrong here

    A legitimate Windows service does not require a UAC prompt to update itself. Services typically run under the LocalSystem or NetworkService accounts that operate with high integrity and can modify system files without user consent. Moreover, genuine Microsoft components are digitally signed and would never use a misspelled executable name or appear out of nowhere while a user is working in a spreadsheet.

  • ✓

    Malware is attempting to escalate privileges.

    Why this is correct

    Malware frequently attempts to escalate from a standard user token to an administrative one by exploiting the user's trust. The unsolicited UAC consent dialog, especially with a suspiciously named executable, is a classic privilege escalation attempt where the malware seeks to gain a high-integrity process. The correct response is to click 'No' and then investigate the source of the prompt.

  • ✗

    The user accidentally double-clicked a scheduled task.

    Why it's wrong here

    Scheduled tasks are designed to run automatically according to a set trigger, and they employ stored credentials when elevated execution is required. If a task is set to run with administrative privileges, it uses the account's saved password, not an interactive UAC prompt, at runtime. Furthermore, double-clicking a task in the Task Scheduler console simply opens its properties window—it does not execute the task—so this action would not generate a UAC elevation request.

  • ✗

    The antivirus software is performing a system scan.

    Why it's wrong here

    Antivirus software operates through a kernel-mode minifilter driver and a Windows service that runs under the SYSTEM account, giving it unfettered access to the disk and memory without needing a UAC elevation. A user-initiated or scheduled scan executes in that pre-existing high-integrity context, so no consent dialog appears. Seeing a UAC prompt claiming to be from your AV is itself a red flag, because the AV should already have the necessary privileges.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.