easyMultiple Choice
CS0-003 Practice Question: A user opens an invoice document and shortly…
A user opens an invoice document and shortly afterward the endpoint runs wscript.exe from the user's profile. Which detection logic is most relevant?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between process execution anomalies and unrelated system events, so the trap here is that candidates may confuse a script interpreter launch with generic system performance issues or authentication events, missing the critical parent-child process chain that defines the attack vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Office document spawning a script interpreter from a user context
The correct detection logic is 'Office document spawning a script interpreter from a user context' because the scenario describes a classic phishing attack where a malicious macro or embedded script in an invoice document launches wscript.exe (a Windows Script Host interpreter) from the user's profile directory. This behavior is a strong indicator of script-based malware execution, as legitimate Office documents rarely spawn script interpreters directly from user-writable paths. The detection logic specifically targets the parent-child process relationship between an Office application (e.g., WINWORD.EXE, EXCEL.EXE) and wscript.exe, which is a common technique used by attackers to bypass application whitelisting and execute arbitrary code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Office document spawning a script interpreter from a user context
Why this is correct
When a user opens a malicious Office document, embedded macros or OLE objects can trigger the execution of code. This often involves the Office application (e.g., Word, Excel) launching a script interpreter like PowerShell, cmd.exe, or wscript.exe under the user's security context. This process chain (Office app spawning a script interpreter) is a classic initial access vector for malware, allowing attackers to download further payloads or establish persistence on the compromised system.
- ✗
A password expiry warning
Why it's wrong here
A password expiry warning is a standard operating system or domain controller notification, indicating that a user's authentication credential will soon expire. This is a routine security prompt related to account management and has no direct causal relationship with a user opening a document or any subsequent malicious script execution. It is an independent event unrelated to process chain anomalies.
- ✗
High CPU usage on the print server
Why it's wrong here
High CPU usage on a print server typically indicates heavy print job processing, driver issues, or potential resource exhaustion on that specific server. While a print server could theoretically be compromised, its CPU load is not directly linked to a user opening a document on their workstation and initiating a suspicious process chain involving a script interpreter. These are distinct events occurring in different parts of the network infrastructure.
- ✗
Successful DHCP renewal
Why it's wrong here
A successful DHCP renewal is a routine network protocol operation where a client device requests and receives an updated IP address lease from a DHCP server. This is a normal, expected background process for maintaining network connectivity and has no direct correlation with a user opening a document or the execution of any scripts, malicious or otherwise. It simply confirms the client maintains network access.
Go deeper
Related to this question
Learn chapter
Critical Windows Event IDs for Security
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.