Courseiva
mediumMultiple Select

CS0-003 Practice Question: A detection engineer is writing a Sigma rule for…

A detection engineer is writing a Sigma rule for suspicious rundll32 usage. Which fields should be included? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the distinction between relevant process-level telemetry (command line, parent process) and irrelevant hardware or peripheral data, so candidates must recognize that Sigma rules are strictly for log-based detection of execution artifacts, not system health or inventory fields.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command line containing unusual DLL path or URL pattern

Sigma rules for suspicious rundll32 usage focus on detecting abnormal command-line arguments, such as DLL paths from unusual locations (e.g., temp directories, network shares) or URLs that indicate remote payload retrieval. The 'Command line' field is critical because rundll32.exe is a legitimate Windows binary often abused by attackers to execute malicious DLLs, and anomalous patterns in its arguments are a strong indicator of compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Command line containing unusual DLL path or URL pattern

    Why this is correct

    For rundll32.exe, the command-line arguments are paramount for distinguishing legitimate system operations from malicious activity. Attackers frequently leverage rundll32.exe to execute arbitrary DLLs, often from unusual or temporary paths, or even to initiate network connections to command-and-control (C2) servers via embedded URLs. Detecting these anomalous patterns within the command line is a high-fidelity indicator of compromise, as it directly reveals the attacker's intended payload or communication channel. This approach effectively identifies abuse of a legitimate binary.

  • ✗

    Desk phone extension

    Why it's wrong here

    A desk phone extension is an organizational asset detail primarily used for communication and inventory management, completely unrelated to host-based security telemetry. It provides no insight into process execution, file system activity, network connections, or any other behavioral indicators that a detection engineer would monitor on an endpoint. Therefore, incorporating such information into a Sigma rule for suspicious process activity would be irrelevant and yield no actionable security intelligence.

  • ✗

    Laptop battery health

    Why it's wrong here

    Laptop battery health is a hardware-level metric indicating the physical condition and lifespan of a device's power source. While important for IT asset management, it offers no correlation or relevance to the detection of suspicious process execution or other security-related behaviors on an endpoint. A detection engineer's focus is on software activity, system calls, and network interactions, not the operational status of internal hardware components like the battery.

  • ✓

    Image or process name matching rundll32.exe

    Why this is correct

    Identifying rundll32.exe as the executed image or process name is a fundamental first step in detecting its potential abuse, as it establishes the specific binary under scrutiny. While rundll32.exe is a legitimate Windows utility, its presence in process logs is a necessary condition for further analysis, especially since it's a common "Living Off The Land" (LotL) binary. This initial match provides the context for subsequent, more granular checks on its command-line arguments and parent-child relationships to differentiate benign from malicious invocations.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.