CS0-003 Security Operations Practice Question
During a threat hunt, an analyst uses osquery to query endpoints for processes that have spawned from Microsoft Word but have network connections. Which of the following TTPs does this technique most likely detect?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spearphishing attachment leading to macro execution
Attackers often use macro-enabled documents to execute code, making Word spawn abnormal child processes like PowerShell or cmd.exe, which then connect outbound.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pass-the-hash attack
Why it's wrong here
Pass-the-hash is a lateral movement technique where an attacker uses a captured NTLM hash to authenticate to remote systems. It does not involve Microsoft Word spawning suspicious child processes like PowerShell or cmd.exe, which is the behavior typically captured by osquery in this scenario.
- ✓
Spearphishing attachment leading to macro execution
Why this is correct
When a user opens a malicious spearphishing attachment, embedded VBA macros often execute and spawn child processes such as PowerShell, cmd.exe, or lolbins to download secondary payloads. Detecting Microsoft Word (winword.exe) spawning these command-line interpreters via osquery is a classic indicator of this initial access technique.
- ✗
Kerberoasting
Why it's wrong here
Kerberoasting is a post-exploitation technique targeting Active Directory service accounts by requesting Kerberos Ticket Granting Service (TGS) tickets and cracking them offline. This attack occurs purely within Active Directory authentication traffic and does not manifest as a productivity application spawning shell processes on an endpoint.
- ✗
Data exfiltration over DNS
Why it's wrong here
Data exfiltration over DNS involves encoding stolen data into DNS queries and sending them to an attacker-controlled authoritative nameserver. While highly malicious, this network-layer evasion technique is unrelated to endpoint process-spawning behaviors, such as Word launching command-line utilities.
Go deeper
Related to this question
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.