Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

A threat hunter is analyzing EDR telemetry and discovers that the process svchost.exe spawned a child process powershell.exe. The powershell.exe then established a network connection to an external IP address. Which of the following best describes this behavior in the context of threat hunting?

⚠ Common exam trap

CS0-004 often tests whether candidates can distinguish between legitimate Windows process behavior and LOLBin abuse — the trap is assuming that because svchost.exe is a trusted system process, any activity it initiates is benign.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Living off the land binary (LOLBin) usage

The behavior described — svchost.exe spawning powershell.exe, which then makes an outbound network connection — is a classic example of a Living off the Land Binary (LOLBin) attack. LOLBins are legitimate, signed Windows executables (like PowerShell, certutil, mshta, regsvr32) that adversaries abuse to blend malicious activity into normal system noise, evading signature-based detection. Because svchost.exe is a trusted system process, its child processes are often overlooked by naive detection rules, making this pattern a high-fidelity threat-hunting indicator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A Windows update process

    Why it's wrong here

    Windows Update operates through wuauserv and the Windows Update Agent communicating with Microsoft's update servers, not by spawning a PowerShell child process from svchost.exe that then reaches out to an arbitrary external IP. Legitimate update traffic also uses well-known Microsoft endpoints, not unattributed addresses, making this attribution inconsistent with the telemetry.

  • ✗

    Normal administrative activity

    Why it's wrong here

    Administrators invoking PowerShell typically do so from an interactive console, RDP session, or a scheduled task with a documented parent process, not as a child of the svchost.exe service-hosting process. Svchost spawning powershell.exe is an atypical parent-child relationship that administrative workflows do not normally produce.

  • ✗

    A false positive from EDR

    Why it's wrong here

    Dismissing the alert as a false positive ignores the well-documented adversary pattern of abusing trusted Windows processes as launchers; svchost.exe spawning powershell.exe followed by an outbound connection matches known command-and-control staging behavior and must be triaged rather than closed without investigation.

  • ✓

    Living off the land binary (LOLBin) usage

    Why this is correct

    This is a living-off-the-land binary technique: adversaries hijack a legitimate, digitally signed process like svchost.exe to launch PowerShell so the activity blends into normal system noise and evades signature-based defenses. The subsequent external network connection from the PowerShell child strongly suggests staged malware download or C2 beaconing, warranting immediate containment and further EDR correlation.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.