Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

An analyst is investigating a potential compromise on a Windows endpoint. EDR telemetry shows that 'powershell.exe' was launched by 'svchost.exe', which in turn was spawned by 'services.exe'. The analyst observes that 'powershell.exe' then executed a script that downloaded an executable. What should the analyst be most concerned about?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

This indicates a potential LOLBin attack using svchost.exe to launch powershell.exe

Svchost.exe hosting a child process like powershell.exe is unusual. This parent-child relationship suggests a LOLBin (living off the land) attack, where an attacker abuses legitimate Windows binaries to execute malicious code. The script download further indicates compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Services.exe spawning svchost.exe is a sign of malware infection

    Why it's wrong here

    Services.exe spawning svchost.exe is the expected, benign lineage on any Windows system, since services.exe is the Service Control Manager that launches every service-hosted DLL through svchost.exe as part of normal boot and runtime operation. Flagging this relationship as malware evidence misidentifies the normal segment of the chain and overlooks the actual anomaly further down.

  • ✗

    Powershell.exe downloading an executable is a false positive from Windows Update

    Why it's wrong here

    Windows Update does not route its download or installation activity through an interactively-scripted powershell.exe process spawned beneath svchost.exe; that update mechanism uses its own dedicated service processes and Microsoft-signed endpoints. Attributing this chain to Windows Update misreads legitimate update telemetry and would cause the analyst to dismiss a genuine intrusion indicator.

  • ✓

    This indicates a potential LOLBin attack using svchost.exe to launch powershell.exe

    Why this is correct

    This chain matches a living-off-the-land binary (LOLBin) technique in which an adversary abuses the trusted svchost.exe process, often via a hijacked or malicious service DLL, to spawn powershell.exe and execute a downloader script while evading signature-based detection. Because svchost.exe is inherently trusted and its child processes are rarely scrutinized, this parent-child anomaly combined with the subsequent executable download is a strong indicator of active compromise requiring immediate isolation and deeper forensic review.

  • ✗

    Svchost.exe spawning powershell.exe is a normal Windows operation

    Why it's wrong here

    Svchost.exe hosts Windows service DLLs and has no legitimate operational need to launch an interactive shell like powershell.exe; this parent-child pairing does not occur in standard Windows service behavior. Characterizing it as normal would cause the analyst to overlook a textbook indicator of process-lineage abuse used to evade detection.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.