CS0-003 Security Operations Practice Question
A security analyst is creating a Sigma rule to detect suspicious usage of 'schtasks.exe' to create a scheduled task that runs an encoded PowerShell command. Which log source is most appropriate for this rule?
⚠ Common exam trap
The trap is assuming the PowerShell operational log is the best source because the payload is PowerShell — but the detection target is the schtasks.exe process creation, which only process-creation telemetry captures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sysmon Event ID 1 (Process creation)
Sysmon Event ID 1 captures process creation with rich metadata including the full command line, parent process, hashes, and user context — exactly what's needed to detect 'schtasks.exe' spawning with an encoded PowerShell payload. Sigma rules map to log sources that expose these fields, and Sysmon EID 1 is the canonical source for process-creation-based detections. This lets the rule match on Image, CommandLine, and ParentImage to catch the suspicious pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Security Event Log (Event ID 4624)
Why it's wrong here
Windows Security Event ID 4624 specifically records successful account logon events, capturing details like logon type and target user security identifier. It does not log process execution details or command-line arguments, making it useless for a Sigma rule targeting the execution of binaries like schtasks.exe.
- ✓
Sysmon Event ID 1 (Process creation)
Why this is correct
Sysmon Event ID 1 provides highly detailed telemetry regarding process creation, including the parent process, command-line arguments, and file hashes. This rich context is essential for Sigma rules designed to detect suspicious command-line flags or anomalous parent-child process relationships.
- ✗
DNS server log
Why it's wrong here
DNS server logs record domain name resolution queries and responses, which are critical for identifying network-based indicators of compromise like beaconing. However, they lack any visibility into local endpoint activity, such as process spawning or command-line execution parameters.
- ✗
Windows PowerShell operational log
Why it's wrong here
The Windows PowerShell Operational log (such as Event ID 4104) records script block execution and PowerShell commands. While useful for detecting malicious scripts, it does not capture the execution of native Windows binaries like schtasks.exe when spawned outside of a PowerShell session.
Go deeper
Related to this question
Learn chapter
Container Image Vulnerability Scanning
Key term
Metadata
Metadata is data that describes other data, providing context such as when a file was created, who created it, or its size.
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.