Courseiva
mediumMultiple Choice

PowerShell Encoded Command from Winword: Triage for CySA+

An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot? In the alert triage phase, Which action gives the analyst the clearest next triage step?

Quick Answer

The answer is to decode the command and inspect the process tree, parent document, and network destination. This is correct because a PowerShell encoded command from winword.exe is a classic indicator of a macro-enabled phishing attack, where the encoded string hides the attacker’s payload from initial detection. Decoding it reveals the specific script logic, while examining the process tree confirms the execution chain from winword.exe to powershell.exe, and the parent document identifies the malicious attachment. On the CompTIA CySA+ CS0-003 exam, this scenario tests your ability to perform alert triage by correlating process ancestry with network artifacts, a common trap being to jump to blocking the IP without first understanding the infection vector. Remember the mnemonic “Decode, Tree, Doc, Net” to recall the four-part pivot: decode the command, inspect the process tree, examine the parent document, and analyze the network destination.

⚠ Common exam trap

The CS0-004 exam often tests the candidate's ability to prioritize investigative actions over reactive or destructive measures, trapping those who choose to disable logging or perform mass reimaging instead of conducting a structured forensic analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Decode the command and inspect the process tree, parent document, and network destination

Decoding the encoded PowerShell command reveals the attacker's intent, inspecting the process tree shows the execution chain from winword.exe to powershell.exe, examining the parent document identifies the malicious attachment, and analyzing the network destination uncovers the C2 server. This systematic approach provides the clearest next triage step by correlating the initial infection vector with the subsequent malicious activity, enabling the analyst to contain the threat effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the SIEM parser for PowerShell events

    Why it's wrong here

    Disabling the parser blinds detection of the very PowerShell activity under investigation and removes evidence from the SIEM. The pivot is decoding the encoded command and correlating the parent-child process chain. Parser changes belong to tuning after an investigation concludes, not during active triage.

  • ✓

    Decode the command and inspect the process tree, parent document, and network destination

    Why this is correct

    The encoded PowerShell spawned by winword.exe indicates a malicious macro or exploit; decoding the command reveals its intent, while the process tree, parent document and destination IP establish scope and command-and-control. Together these give the clearest evidence-driven pivot before containment decisions.

  • ✗

    Reimage every workstation in the department

    Why it's wrong here

    Reimaging the whole department destroys volatile evidence and disrupts unaffected hosts before scope is known. The triage pivot is decoding the encoded PowerShell command and checking the process tree and network connections. Mass reimaging is a containment action reserved for confirmed widespread compromise, not an investigative step.

  • ✗

    Close the alert because HTTPS is expected traffic

    Why it's wrong here

    HTTPS being common does not explain winword.exe spawning encoded PowerShell, which is the suspicious behaviour requiring investigation. Closing discards the alert without decoding the command or checking the endpoint. Routine HTTPS from a browser would be benign, but this parent-child chain is not.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CS0-004

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot that balances containment with evidence preservation?

medium
  • A.Close the alert because HTTPS is expected traffic
  • B.Disable the SIEM parser for PowerShell events
  • ✓ C.Decode the command and inspect the process tree, parent document, and network destination
  • D.Reimage every workstation in the department

Why C: The encoded PowerShell command is the most direct artifact of the attacker's intent; decoding it reveals the executed payload, while inspecting the process tree confirms the parent-child relationship (winword.exe spawning powershell.exe), the parent document identifies the phishing vector, and the network destination pinpoints the C2 server. This triage provides the evidence needed for containment without destroying forensic data.

Variation 2. An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot? In the detection engineering phase, Which detection or tuning approach would reduce noise without losing the signal?

medium
  • ✓ A.Decode the command and inspect the process tree, parent document, and network destination
  • B.Disable the SIEM parser for PowerShell events
  • C.Reimage every workstation in the department
  • D.Close the alert because HTTPS is expected traffic

Why A: The first analytic pivot in a suspected malware infection via phishing must decode the encoded PowerShell command to understand the attacker's intent, inspect the process tree to confirm parent-child relationships (winword.exe spawning powershell.exe), analyze the parent document for malicious macros or exploits, and examine the network destination to identify potential C2 infrastructure. This approach aligns with the Pyramid of Pain and ensures the analyst gathers actionable intelligence before any containment or tuning decisions.

Variation 3. An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot? In the root-cause analysis phase, Which finding would most directly explain the activity?

medium
  • A.Disable the SIEM parser for PowerShell events
  • B.Reimage every workstation in the department
  • C.Close the alert because HTTPS is expected traffic
  • ✓ D.Decode the command and inspect the process tree, parent document, and network destination

Why D: The stem has a grammatical and structural error where two distinct questions are combined. The second question ('In the root-cause analysis phase, Which finding would most directly explain the activity?') does not align well with the provided options, whereas the first question ('What is the BEST first analytic pivot?') perfectly matches Option D. Cleaning up the stem to ask a single, clear question makes the item professional and valid.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.