CS0-003 Security Operations Practice Question
A threat hunter is reviewing osquery data from endpoints and notices that the Windows Registry key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' contains an entry for 'C:\Users\Public\svchost.exe'. Which of the following best describes the significance of this finding?
⚠ Common exam trap
CS0-004 often tests the misconception that any file named svchost.exe is legitimate, but the path is the key indicator; candidates might overlook the non-standard location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Suggests persistence via a malicious binary masquerading as svchost.exe
The Run key is a common persistence location in the Windows Registry. The entry points to 'C:\Users\Public\svchost.exe', which is suspicious because legitimate svchost.exe resides in C:\Windows\System32 and is never in the Users\Public folder. This strongly suggests a malicious binary masquerading as a legitimate system process to maintain persistence and evade detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confirms a false positive because svchost.exe is always legitimate
Why it's wrong here
Dismissing this finding as a false positive is a critical error because adversaries frequently name malicious payloads "svchost.exe" to blend in with legitimate Windows processes. While the genuine Service Host process is vital for Windows operations, its presence in an unusual directory like the Public folder indicates masquerading rather than legitimate system activity.
- ✗
Indicates a scheduled task has been created
Why it's wrong here
The registry Run key is designed to launch programs automatically upon user login, not to schedule tasks. Scheduled tasks are managed via the Task Scheduler engine and are stored in different registry hives and file system locations, such as the System32 Tasks folder, rather than the standard Run keys.
- ✓
Suggests persistence via a malicious binary masquerading as svchost.exe
Why this is correct
This is correct because the registry Run key is a classic persistence mechanism used to ensure malware executes automatically when a user logs in. Furthermore, legitimate "svchost.exe" binaries must execute exclusively from the System32 directory; finding an executable with this name in a user-writable directory like the Public folder strongly indicates a masquerading technique.
- ✗
Indicates a legitimate application installed for all users
Why it's wrong here
Legitimate software installations intended for all users typically place their binaries in protected directories such as Program Files or Program Files (x86). They do not drop system-named executables like "svchost.exe" into the Public user directory, which is a common staging ground for malware due to its relaxed write permissions.
Go deeper
Related to this question
Learn chapter
Software Bill of Materials (SBOM)
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.