Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

During a threat hunt, an analyst uses osquery to query endpoints for processes that have spawned from Microsoft Word but have network connections. Which of the following TTPs does this technique most likely detect?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spearphishing attachment leading to macro execution

Attackers often use macro-enabled documents to execute code, making Word spawn abnormal child processes like PowerShell or cmd.exe, which then connect outbound.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pass-the-hash attack

    Why it's wrong here

    Pass-the-hash is a lateral movement technique where an attacker uses a captured NTLM hash to authenticate to remote systems. It does not involve Microsoft Word spawning suspicious child processes like PowerShell or cmd.exe, which is the behavior typically captured by osquery in this scenario.

  • ✓

    Spearphishing attachment leading to macro execution

    Why this is correct

    When a user opens a malicious spearphishing attachment, embedded VBA macros often execute and spawn child processes such as PowerShell, cmd.exe, or lolbins to download secondary payloads. Detecting Microsoft Word (winword.exe) spawning these command-line interpreters via osquery is a classic indicator of this initial access technique.

  • ✗

    Kerberoasting

    Why it's wrong here

    Kerberoasting is a post-exploitation technique targeting Active Directory service accounts by requesting Kerberos Ticket Granting Service (TGS) tickets and cracking them offline. This attack occurs purely within Active Directory authentication traffic and does not manifest as a productivity application spawning shell processes on an endpoint.

  • ✗

    Data exfiltration over DNS

    Why it's wrong here

    Data exfiltration over DNS involves encoding stolen data into DNS queries and sending them to an attacker-controlled authoritative nameserver. While highly malicious, this network-layer evasion technique is unrelated to endpoint process-spawning behaviors, such as Word launching command-line utilities.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.