Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

A threat hunter is creating a Sigma rule to detect a specific TTP where an attacker uses reg.exe to create a Run key for persistence. Which of the following Sigma rule event selectors would best detect this activity?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EventID: 13 (Registry Value Set) AND TargetObject: '*\CurrentVersion\Run*'

Registry persistence via Run keys is commonly achieved by modifying HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Sigma rules targeting registry add/modify events with that path will detect it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EventID: 4688 (Process Creation) AND ParentImage: '*reg.exe*'

    Why it's wrong here

    Windows Security Event ID 4688 tracks process creation events. Filtering for a parent image of reg.exe identifies child processes spawned by the registry console tool, which does not directly capture the actual modification of registry keys or values. This approach fails to detect registry changes made via APIs, PowerShell, or other non-child-process-spawning methods.

  • ✓

    EventID: 13 (Registry Value Set) AND TargetObject: '*\CurrentVersion\Run*'

    Why this is correct

    Sysmon Event ID 13 specifically monitors registry value modifications, making it highly effective for tracking persistence mechanisms. By targeting the \\CurrentVersion\\Run key path within the TargetObject field, this rule directly alerts on attempts to establish autostart execution points, regardless of the process initiating the change.

  • ✗

    EventID: 4657 (Registry modification) AND ObjectName: '*\RunOnce*'

    Why it's wrong here

    While Windows Security Event ID 4657 monitors registry modifications, searching for \\RunOnce targets a distinct, one-time execution key rather than the standard persistent Run key. Additionally, Event ID 4657 uses the ObjectName field to log the key path, whereas Sysmon-style rules or specific schema mappings might expect TargetObject, leading to potential parsing failures.

  • ✗

    EventID: 1 (Process Creation) AND CommandLine: '*reg.exe*'

    Why it's wrong here

    Sysmon Event ID 1 logs process creation, and while monitoring reg.exe execution in the command line can identify manual registry manipulation, it does not guarantee a modification occurred to the specific persistence keys. This broad approach generates significant noise and high false-positive rates because legitimate administrative scripts frequently execute reg.exe for benign queries.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.