hardMultiple Select
CS0-003 Practice Question: A malware alert shows a signed binary performing…
A malware alert shows a signed binary performing suspicious actions. Which facts help decide whether it is living-off-the-land abuse? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the misconception that a signed binary from a trusted vendor is inherently safe, but the trap here is that LotL abuse specifically exploits the trust in signed administrative tools, so candidates must focus on behavioral anomalies (parent process, command-line actions) rather than the binary's signature or vendor name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The binary is normally administrative but launched from an unusual parent process
Living-off-the-land (LotL) abuse often involves legitimate administrative binaries (e.g., PowerShell, certutil, wmic) being executed from an unexpected parent process, such as a Microsoft Office application or a script host. This deviation from the normal process tree (e.g., cmd.exe or explorer.exe spawning the binary) is a strong indicator of malicious intent, as attackers leverage trusted tools to evade detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The binary is normally administrative but launched from an unusual parent process
Why this is correct
Legitimate administrative binaries, such as PowerShell or wmic, are frequently abused by attackers in Living off the Land (LotL) attacks. When a trusted, signed binary is spawned by an anomalous parent process like a web server (w3wp.exe) or a document viewer, it strongly indicates a compromise or exploit execution rather than normal administrative activity.
- ✓
The command line performs download, encode, dump, or remote-execution behaviour
Why this is correct
Even if a binary is digitally signed and trusted, the specific command-line arguments passed to it can reveal malicious intent. For instance, using certutil to download files, using PowerShell to decode Base64 payloads, or using built-in tools to dump LSASS memory represents highly suspicious behavior that bypasses traditional signature-based detection.
- ✗
The binary has a familiar vendor name only
Why it's wrong here
Relying solely on a familiar vendor name or a valid digital signature is insufficient because attackers can hijack legitimate binaries through DLL side-loading or exploit them via command-line arguments. Additionally, threat actors can sign malware using stolen certificates or spoof vendor metadata to evade simple static analysis filters.
- ✗
The endpoint wallpaper is unchanged
Why it's wrong here
The state of the endpoint's desktop wallpaper is a superficial artifact that does not correlate with binary execution or malicious activity. While some ransomware families may alter the desktop background to display a ransom note, the lack of wallpaper modification has no diagnostic value when analyzing whether a signed binary is performing suspicious actions.
Go deeper
Related to this question
Learn chapter
Privileged Access Management and PAM Tools
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.