mediumMultiple Choice
PowerShell Encoded Command from Winword: Triage for CySA+
An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot? In the alert triage phase, Which action gives the analyst the clearest next triage step?
Quick Answer
The answer is to decode the command and inspect the process tree, parent document, and network destination. This is correct because a PowerShell encoded command from winword.exe is a classic indicator of a macro-enabled phishing attack, where the encoded string hides the attacker’s payload from initial detection. Decoding it reveals the specific script logic, while examining the process tree confirms the execution chain from winword.exe to powershell.exe, and the parent document identifies the malicious attachment. On the CompTIA CySA+ CS0-003 exam, this scenario tests your ability to perform alert triage by correlating process ancestry with network artifacts, a common trap being to jump to blocking the IP without first understanding the infection vector. Remember the mnemonic “Decode, Tree, Doc, Net” to recall the four-part pivot: decode the command, inspect the process tree, examine the parent document, and analyze the network destination.
⚠ Common exam trap
The CS0-004 exam often tests the candidate's ability to prioritize investigative actions over reactive or destructive measures, trapping those who choose to disable logging or perform mass reimaging instead of conducting a structured forensic analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Decode the command and inspect the process tree, parent document, and network destination
Decoding the encoded PowerShell command reveals the attacker's intent, inspecting the process tree shows the execution chain from winword.exe to powershell.exe, examining the parent document identifies the malicious attachment, and analyzing the network destination uncovers the C2 server. This systematic approach provides the clearest next triage step by correlating the initial infection vector with the subsequent malicious activity, enabling the analyst to contain the threat effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the SIEM parser for PowerShell events
Why it's wrong here
Disabling the parser blinds detection of the very PowerShell activity under investigation and removes evidence from the SIEM. The pivot is decoding the encoded command and correlating the parent-child process chain. Parser changes belong to tuning after an investigation concludes, not during active triage.
- ✓
Decode the command and inspect the process tree, parent document, and network destination
Why this is correct
The encoded PowerShell spawned by winword.exe indicates a malicious macro or exploit; decoding the command reveals its intent, while the process tree, parent document and destination IP establish scope and command-and-control. Together these give the clearest evidence-driven pivot before containment decisions.
- ✗
Reimage every workstation in the department
Why it's wrong here
Reimaging the whole department destroys volatile evidence and disrupts unaffected hosts before scope is known. The triage pivot is decoding the encoded PowerShell command and checking the process tree and network connections. Mass reimaging is a containment action reserved for confirmed widespread compromise, not an investigative step.
- ✗
Close the alert because HTTPS is expected traffic
Why it's wrong here
HTTPS being common does not explain winword.exe spawning encoded PowerShell, which is the suspicious behaviour requiring investigation. Closing discards the alert without decoding the command or checking the endpoint. Routine HTTPS from a browser would be benign, but this parent-child chain is not.
Go deeper
Related to this question
Learn chapter
Network Forensics: Packet Capture Analysis
Key term
EDR alert
An EDR alert is a notification generated by Endpoint Detection and Response software when it detects potentially malicious activity or an anomaly on a device like a laptop, server, or workstation.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CS0-004
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot that balances containment with evidence preservation?
medium- A.Close the alert because HTTPS is expected traffic
- B.Disable the SIEM parser for PowerShell events
- ✓ C.Decode the command and inspect the process tree, parent document, and network destination
- D.Reimage every workstation in the department
Why C: The encoded PowerShell command is the most direct artifact of the attacker's intent; decoding it reveals the executed payload, while inspecting the process tree confirms the parent-child relationship (winword.exe spawning powershell.exe), the parent document identifies the phishing vector, and the network destination pinpoints the C2 server. This triage provides the evidence needed for containment without destroying forensic data.
Variation 2. An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot? In the detection engineering phase, Which detection or tuning approach would reduce noise without losing the signal?
medium- ✓ A.Decode the command and inspect the process tree, parent document, and network destination
- B.Disable the SIEM parser for PowerShell events
- C.Reimage every workstation in the department
- D.Close the alert because HTTPS is expected traffic
Why A: The first analytic pivot in a suspected malware infection via phishing must decode the encoded PowerShell command to understand the attacker's intent, inspect the process tree to confirm parent-child relationships (winword.exe spawning powershell.exe), analyze the parent document for malicious macros or exploits, and examine the network destination to identify potential C2 infrastructure. This approach aligns with the Pyramid of Pain and ensures the analyst gathers actionable intelligence before any containment or tuning decisions.
Variation 3. An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot? In the root-cause analysis phase, Which finding would most directly explain the activity?
medium- A.Disable the SIEM parser for PowerShell events
- B.Reimage every workstation in the department
- C.Close the alert because HTTPS is expected traffic
- ✓ D.Decode the command and inspect the process tree, parent document, and network destination
Why D: The stem has a grammatical and structural error where two distinct questions are combined. The second question ('In the root-cause analysis phase, Which finding would most directly explain the activity?') does not align well with the provided options, whereas the first question ('What is the BEST first analytic pivot?') perfectly matches Option D. Cleaning up the stem to ask a single, clear question makes the item professional and valid.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.