Courseiva
hardMultiple Select

CS0-003 Practice Question: A malware alert shows a signed binary performing…

A malware alert shows a signed binary performing suspicious actions. Which facts help decide whether it is living-off-the-land abuse? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the misconception that a signed binary from a trusted vendor is inherently safe, but the trap here is that LotL abuse specifically exploits the trust in signed administrative tools, so candidates must focus on behavioral anomalies (parent process, command-line actions) rather than the binary's signature or vendor name.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The binary is normally administrative but launched from an unusual parent process

Living-off-the-land (LotL) abuse often involves legitimate administrative binaries (e.g., PowerShell, certutil, wmic) being executed from an unexpected parent process, such as a Microsoft Office application or a script host. This deviation from the normal process tree (e.g., cmd.exe or explorer.exe spawning the binary) is a strong indicator of malicious intent, as attackers leverage trusted tools to evade detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The binary is normally administrative but launched from an unusual parent process

    Why this is correct

    Legitimate administrative binaries, such as PowerShell or wmic, are frequently abused by attackers in Living off the Land (LotL) attacks. When a trusted, signed binary is spawned by an anomalous parent process like a web server (w3wp.exe) or a document viewer, it strongly indicates a compromise or exploit execution rather than normal administrative activity.

  • ✓

    The command line performs download, encode, dump, or remote-execution behaviour

    Why this is correct

    Even if a binary is digitally signed and trusted, the specific command-line arguments passed to it can reveal malicious intent. For instance, using certutil to download files, using PowerShell to decode Base64 payloads, or using built-in tools to dump LSASS memory represents highly suspicious behavior that bypasses traditional signature-based detection.

  • ✗

    The binary has a familiar vendor name only

    Why it's wrong here

    Relying solely on a familiar vendor name or a valid digital signature is insufficient because attackers can hijack legitimate binaries through DLL side-loading or exploit them via command-line arguments. Additionally, threat actors can sign malware using stolen certificates or spoof vendor metadata to evade simple static analysis filters.

  • ✗

    The endpoint wallpaper is unchanged

    Why it's wrong here

    The state of the endpoint's desktop wallpaper is a superficial artifact that does not correlate with binary execution or malicious activity. While some ransomware families may alter the desktop background to display a ransom note, the lack of wallpaper modification has no diagnostic value when analyzing whether a signed binary is performing suspicious actions.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.