CS0-003 Security Operations Practice Question
A threat hunter is creating a Sigma rule to detect a specific TTP where an attacker uses reg.exe to create a Run key for persistence. Which of the following Sigma rule event selectors would best detect this activity?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EventID: 13 (Registry Value Set) AND TargetObject: '*\CurrentVersion\Run*'
Registry persistence via Run keys is commonly achieved by modifying HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Sigma rules targeting registry add/modify events with that path will detect it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EventID: 4688 (Process Creation) AND ParentImage: '*reg.exe*'
Why it's wrong here
Windows Security Event ID 4688 tracks process creation events. Filtering for a parent image of reg.exe identifies child processes spawned by the registry console tool, which does not directly capture the actual modification of registry keys or values. This approach fails to detect registry changes made via APIs, PowerShell, or other non-child-process-spawning methods.
- ✓
EventID: 13 (Registry Value Set) AND TargetObject: '*\CurrentVersion\Run*'
Why this is correct
Sysmon Event ID 13 specifically monitors registry value modifications, making it highly effective for tracking persistence mechanisms. By targeting the \\CurrentVersion\\Run key path within the TargetObject field, this rule directly alerts on attempts to establish autostart execution points, regardless of the process initiating the change.
- ✗
EventID: 4657 (Registry modification) AND ObjectName: '*\RunOnce*'
Why it's wrong here
While Windows Security Event ID 4657 monitors registry modifications, searching for \\RunOnce targets a distinct, one-time execution key rather than the standard persistent Run key. Additionally, Event ID 4657 uses the ObjectName field to log the key path, whereas Sysmon-style rules or specific schema mappings might expect TargetObject, leading to potential parsing failures.
- ✗
EventID: 1 (Process Creation) AND CommandLine: '*reg.exe*'
Why it's wrong here
Sysmon Event ID 1 logs process creation, and while monitoring reg.exe execution in the command line can identify manual registry manipulation, it does not guarantee a modification occurred to the specific persistence keys. This broad approach generates significant noise and high false-positive rates because legitimate administrative scripts frequently execute reg.exe for benign queries.
Go deeper
Related to this question
Learn chapter
Advanced Persistent Threat (APT) Groups
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.