Courseiva
easyMultiple Choice

CS0-003 Practice Question: A user opens an invoice document and shortly…

A user opens an invoice document and shortly afterward the endpoint runs wscript.exe from the user's profile. Which detection logic is most relevant?

⚠ Common exam trap

The CS0-004 exam often tests the distinction between process execution anomalies and unrelated system events, so the trap here is that candidates may confuse a script interpreter launch with generic system performance issues or authentication events, missing the critical parent-child process chain that defines the attack vector.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Office document spawning a script interpreter from a user context

The correct detection logic is 'Office document spawning a script interpreter from a user context' because the scenario describes a classic phishing attack where a malicious macro or embedded script in an invoice document launches wscript.exe (a Windows Script Host interpreter) from the user's profile directory. This behavior is a strong indicator of script-based malware execution, as legitimate Office documents rarely spawn script interpreters directly from user-writable paths. The detection logic specifically targets the parent-child process relationship between an Office application (e.g., WINWORD.EXE, EXCEL.EXE) and wscript.exe, which is a common technique used by attackers to bypass application whitelisting and execute arbitrary code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Office document spawning a script interpreter from a user context

    Why this is correct

    When a user opens a malicious Office document, embedded macros or OLE objects can trigger the execution of code. This often involves the Office application (e.g., Word, Excel) launching a script interpreter like PowerShell, cmd.exe, or wscript.exe under the user's security context. This process chain (Office app spawning a script interpreter) is a classic initial access vector for malware, allowing attackers to download further payloads or establish persistence on the compromised system.

  • ✗

    A password expiry warning

    Why it's wrong here

    A password expiry warning is a standard operating system or domain controller notification, indicating that a user's authentication credential will soon expire. This is a routine security prompt related to account management and has no direct causal relationship with a user opening a document or any subsequent malicious script execution. It is an independent event unrelated to process chain anomalies.

  • ✗

    High CPU usage on the print server

    Why it's wrong here

    High CPU usage on a print server typically indicates heavy print job processing, driver issues, or potential resource exhaustion on that specific server. While a print server could theoretically be compromised, its CPU load is not directly linked to a user opening a document on their workstation and initiating a suspicious process chain involving a script interpreter. These are distinct events occurring in different parts of the network infrastructure.

  • ✗

    Successful DHCP renewal

    Why it's wrong here

    A successful DHCP renewal is a routine network protocol operation where a client device requests and receives an updated IP address lease from a DHCP server. This is a normal, expected background process for maintaining network connectivity and has no direct correlation with a user opening a document or the execution of any scripts, malicious or otherwise. It simply confirms the client maintains network access.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.