Courseiva
Security Operations →hardMultiple Select

CS0-003 Security Operations Practice Question

A security analyst is conducting a proactive threat hunt for lateral movement techniques. The analyst examines EDR data for unusual parent-child process relationships. Which three process chains are indicative of lateral movement? (Select THREE.)

⚠ Common exam trap

CS0-004 often tests the ability to distinguish between benign and malicious process chains, and candidates may incorrectly select explorer.exe spawning cmd.exe (a common user action) or rundll32.exe spawning powershell.exe (more associated with execution than lateral movement) as indicators of lateral movement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

svchost.exe spawning schtasks.exe

Option A is correct because svchost.exe normally hosts Windows services and should not directly spawn schtasks.exe; this parent-child chain indicates a service abusing the Task Scheduler to create or run a remote task for lateral movement. Option C is correct because services.exe is the Service Control Manager and spawning cmd.exe directly is anomalous, often reflecting a malicious service or PsExec-style remote service creation used to execute commands on a target host. Option D is correct because wmiprvse.exe is the WMI provider host, and a WMI provider spawning cmd.exe is a classic sign of remote WMI execution (for example, wmic /node: process call create) used for lateral movement. Option B is not indicative by itself because explorer.exe spawning cmd.exe is a common, legitimate user action such as opening a command prompt. Option E is not a reliable lateral-movement indicator because rundll32.exe spawning powershell.exe, while suspicious in some contexts, is a generic execution chain that can occur from local scripts or malware and does not specifically demonstrate lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    svchost.exe spawning schtasks.exe

    Why this is correct

    svchost.exe normally hosts service DLLs and does not spawn schtasks.exe. This parent-child pairing indicates a service being abused to create a scheduled task, a common lateral movement and persistence technique for executing code on a remote host.

  • ✗

    explorer.exe spawning cmd.exe

    Why it's wrong here

    Explorer.exe spawning cmd.exe is a routine user action, such as opening a command prompt from the desktop, and appears constantly in benign telemetry. It is tempting because attackers do abuse shell spawning, but the parent must be an unusual process such as a document reader or web server, not the user shell.

  • ✓

    services.exe spawning cmd.exe

    Why this is correct

    services.exe spawning cmd.exe is anomalous because the Service Control Manager launches service binaries, not interactive shells. This chain typically indicates a malicious service installed remotely to execute commands, a hallmark of lateral movement via PsExec-style techniques.

  • ✓

    wmiprvse.exe spawning cmd.exe

    Why this is correct

    wmiprvse.exe spawning cmd.exe indicates abuse of WMI to execute commands remotely, since the WMI provider host should not launch shells. This parent-child relationship is a well-known lateral movement indicator, often produced by tools such as Impacket's wmiexec.

  • ✗

    rundll32.exe spawning powershell.exe

    Why it's wrong here

    Rundll32 spawning PowerShell is a common administrative and installer pattern, so it lacks the specificity of true lateral-movement chains such as services.exe or wmiprvse.exe launching cmd.exe on a remote host. It tempts because rundll32 is abused for proxy execution, but that indicates defence evasion, not SMB or remote-service lateral movement.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.