Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is creating a Sigma rule to detect suspicious usage of 'schtasks.exe' to create a scheduled task that runs an encoded PowerShell command. Which log source is most appropriate for this rule?

⚠ Common exam trap

The trap is assuming the PowerShell operational log is the best source because the payload is PowerShell — but the detection target is the schtasks.exe process creation, which only process-creation telemetry captures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sysmon Event ID 1 (Process creation)

Sysmon Event ID 1 captures process creation with rich metadata including the full command line, parent process, hashes, and user context — exactly what's needed to detect 'schtasks.exe' spawning with an encoded PowerShell payload. Sigma rules map to log sources that expose these fields, and Sysmon EID 1 is the canonical source for process-creation-based detections. This lets the rule match on Image, CommandLine, and ParentImage to catch the suspicious pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows Security Event Log (Event ID 4624)

    Why it's wrong here

    Windows Security Event ID 4624 specifically records successful account logon events, capturing details like logon type and target user security identifier. It does not log process execution details or command-line arguments, making it useless for a Sigma rule targeting the execution of binaries like schtasks.exe.

  • ✓

    Sysmon Event ID 1 (Process creation)

    Why this is correct

    Sysmon Event ID 1 provides highly detailed telemetry regarding process creation, including the parent process, command-line arguments, and file hashes. This rich context is essential for Sigma rules designed to detect suspicious command-line flags or anomalous parent-child process relationships.

  • ✗

    DNS server log

    Why it's wrong here

    DNS server logs record domain name resolution queries and responses, which are critical for identifying network-based indicators of compromise like beaconing. However, they lack any visibility into local endpoint activity, such as process spawning or command-line execution parameters.

  • ✗

    Windows PowerShell operational log

    Why it's wrong here

    The Windows PowerShell Operational log (such as Event ID 4104) records script block execution and PowerShell commands. While useful for detecting malicious scripts, it does not capture the execution of native Windows binaries like schtasks.exe when spawned outside of a PowerShell session.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.