CS0-003 Security Operations Practice Question
An analyst is investigating a potential compromise on a Windows endpoint. EDR telemetry shows that 'powershell.exe' was launched by 'svchost.exe', which in turn was spawned by 'services.exe'. The analyst observes that 'powershell.exe' then executed a script that downloaded an executable. What should the analyst be most concerned about?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
This indicates a potential LOLBin attack using svchost.exe to launch powershell.exe
Svchost.exe hosting a child process like powershell.exe is unusual. This parent-child relationship suggests a LOLBin (living off the land) attack, where an attacker abuses legitimate Windows binaries to execute malicious code. The script download further indicates compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Services.exe spawning svchost.exe is a sign of malware infection
Why it's wrong here
Services.exe spawning svchost.exe is the expected, benign lineage on any Windows system, since services.exe is the Service Control Manager that launches every service-hosted DLL through svchost.exe as part of normal boot and runtime operation. Flagging this relationship as malware evidence misidentifies the normal segment of the chain and overlooks the actual anomaly further down.
- ✗
Powershell.exe downloading an executable is a false positive from Windows Update
Why it's wrong here
Windows Update does not route its download or installation activity through an interactively-scripted powershell.exe process spawned beneath svchost.exe; that update mechanism uses its own dedicated service processes and Microsoft-signed endpoints. Attributing this chain to Windows Update misreads legitimate update telemetry and would cause the analyst to dismiss a genuine intrusion indicator.
- ✓
This indicates a potential LOLBin attack using svchost.exe to launch powershell.exe
Why this is correct
This chain matches a living-off-the-land binary (LOLBin) technique in which an adversary abuses the trusted svchost.exe process, often via a hijacked or malicious service DLL, to spawn powershell.exe and execute a downloader script while evading signature-based detection. Because svchost.exe is inherently trusted and its child processes are rarely scrutinized, this parent-child anomaly combined with the subsequent executable download is a strong indicator of active compromise requiring immediate isolation and deeper forensic review.
- ✗
Svchost.exe spawning powershell.exe is a normal Windows operation
Why it's wrong here
Svchost.exe hosts Windows service DLLs and has no legitimate operational need to launch an interactive shell like powershell.exe; this parent-child pairing does not occur in standard Windows service behavior. Characterizing it as normal would cause the analyst to overlook a textbook indicator of process-lineage abuse used to evade detection.
Go deeper
Related to this question
Learn chapter
Business Email Compromise (BEC) Response
Key term
Living off the land
Living off the land is an attack technique where cybercriminals use the legitimate tools and software already installed on a computer system to carry out malicious activities, making them harder to detect.
Key term
EDR
Endpoint Detection and Response (EDR) is a cybersecurity technology that continuously monitors endpoint devices to detect, investigate, and respond to advanced threats.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.