CS0-003 Security Operations Practice Question
A threat hunter is analyzing EDR telemetry and discovers that the process svchost.exe spawned a child process powershell.exe. The powershell.exe then established a network connection to an external IP address. Which of the following best describes this behavior in the context of threat hunting?
⚠ Common exam trap
CS0-004 often tests whether candidates can distinguish between legitimate Windows process behavior and LOLBin abuse — the trap is assuming that because svchost.exe is a trusted system process, any activity it initiates is benign.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Living off the land binary (LOLBin) usage
The behavior described — svchost.exe spawning powershell.exe, which then makes an outbound network connection — is a classic example of a Living off the Land Binary (LOLBin) attack. LOLBins are legitimate, signed Windows executables (like PowerShell, certutil, mshta, regsvr32) that adversaries abuse to blend malicious activity into normal system noise, evading signature-based detection. Because svchost.exe is a trusted system process, its child processes are often overlooked by naive detection rules, making this pattern a high-fidelity threat-hunting indicator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Windows update process
Why it's wrong here
Windows Update operates through wuauserv and the Windows Update Agent communicating with Microsoft's update servers, not by spawning a PowerShell child process from svchost.exe that then reaches out to an arbitrary external IP. Legitimate update traffic also uses well-known Microsoft endpoints, not unattributed addresses, making this attribution inconsistent with the telemetry.
- ✗
Normal administrative activity
Why it's wrong here
Administrators invoking PowerShell typically do so from an interactive console, RDP session, or a scheduled task with a documented parent process, not as a child of the svchost.exe service-hosting process. Svchost spawning powershell.exe is an atypical parent-child relationship that administrative workflows do not normally produce.
- ✗
A false positive from EDR
Why it's wrong here
Dismissing the alert as a false positive ignores the well-documented adversary pattern of abusing trusted Windows processes as launchers; svchost.exe spawning powershell.exe followed by an outbound connection matches known command-and-control staging behavior and must be triaged rather than closed without investigation.
- ✓
Living off the land binary (LOLBin) usage
Why this is correct
This is a living-off-the-land binary technique: adversaries hijack a legitimate, digitally signed process like svchost.exe to launch PowerShell so the activity blends into normal system noise and evades signature-based defenses. The subsequent external network connection from the PowerShell child strongly suggests staged malware download or C2 beaconing, warranting immediate containment and further EDR correlation.
Go deeper
Related to this question
Learn chapter
Supply Chain Attack Response
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
EDR
Endpoint Detection and Response (EDR) is a cybersecurity technology that continuously monitors endpoint devices to detect, investigate, and respond to advanced threats.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.