Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A threat hunter is reviewing osquery data from endpoints and notices that the Windows Registry key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' contains an entry for 'C:\Users\Public\svchost.exe'. Which of the following best describes the significance of this finding?

⚠ Common exam trap

CS0-004 often tests the misconception that any file named svchost.exe is legitimate, but the path is the key indicator; candidates might overlook the non-standard location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Suggests persistence via a malicious binary masquerading as svchost.exe

The Run key is a common persistence location in the Windows Registry. The entry points to 'C:\Users\Public\svchost.exe', which is suspicious because legitimate svchost.exe resides in C:\Windows\System32 and is never in the Users\Public folder. This strongly suggests a malicious binary masquerading as a legitimate system process to maintain persistence and evade detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Confirms a false positive because svchost.exe is always legitimate

    Why it's wrong here

    Dismissing this finding as a false positive is a critical error because adversaries frequently name malicious payloads "svchost.exe" to blend in with legitimate Windows processes. While the genuine Service Host process is vital for Windows operations, its presence in an unusual directory like the Public folder indicates masquerading rather than legitimate system activity.

  • ✗

    Indicates a scheduled task has been created

    Why it's wrong here

    The registry Run key is designed to launch programs automatically upon user login, not to schedule tasks. Scheduled tasks are managed via the Task Scheduler engine and are stored in different registry hives and file system locations, such as the System32 Tasks folder, rather than the standard Run keys.

  • ✓

    Suggests persistence via a malicious binary masquerading as svchost.exe

    Why this is correct

    This is correct because the registry Run key is a classic persistence mechanism used to ensure malware executes automatically when a user logs in. Furthermore, legitimate "svchost.exe" binaries must execute exclusively from the System32 directory; finding an executable with this name in a user-writable directory like the Public folder strongly indicates a masquerading technique.

  • ✗

    Indicates a legitimate application installed for all users

    Why it's wrong here

    Legitimate software installations intended for all users typically place their binaries in protected directories such as Program Files or Program Files (x86). They do not drop system-named executables like "svchost.exe" into the Public user directory, which is a common staging ground for malware due to its relaxed write permissions.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.