Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

During a threat hunting exercise, an analyst uses osquery to query process events on endpoints. They discover a process named 'svchost.exe' running under a user account with parent process 'cmd.exe'. Which of the following describes this observation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Potential LOLBin abuse with anomalous parent-child relationship

svchost.exe should normally run under SYSTEM or NETWORK SERVICE with 'services.exe' as parent. A user-level svchost.exe with cmd.exe parent indicates a potential LOLBin misuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Normal behavior for Windows services

    Why it's wrong here

    While svchost.exe is a legitimate Windows system process used to host service DLLs, it normally executes under system accounts like SYSTEM, LocalService, or NetworkService. It is highly anomalous for it to be spawned by a user-controlled command interpreter like cmd.exe or to run under a standard user's security context. This deviation from the baseline strongly indicates malicious activity rather than standard operating system behavior.

  • ✗

    Evidence of a DLL injection attack

    Why it's wrong here

    DLL injection involves forcing an existing, running process to load a malicious dynamic-link library from disk. This technique manipulates the memory space of a target process but does not alter the process creation hierarchy or spawn a new process. Therefore, seeing cmd.exe act as the parent process to svchost.exe points to anomalous process creation rather than active memory injection.

  • ✓

    Potential LOLBin abuse with anomalous parent-child relationship

    Why this is correct

    Attackers frequently leverage legitimate binaries like svchost.exe as Living off the Land Binaries (LOLBins) to evade detection and bypass application whitelisting. In a standard Windows environment, services.exe is the exclusive parent process of svchost.exe. Observing cmd.exe spawning svchost.exe represents an anomalous parent-child relationship that strongly indicates an adversary attempting to masquerade malicious execution under a trusted system process name.

  • ✗

    Indicative of a process hollowing attack

    Why it's wrong here

    Process hollowing is an evasion technique where an attacker spawns a legitimate process in a suspended state, unmaps its memory, and replaces it with malicious payload code. While svchost.exe is a common target for hollowing, the detection of an anomalous parent-child relationship (such as cmd.exe spawning svchost.exe) is a distinct telemetry indicator of improper process creation. Process hollowing itself is typically identified through memory analysis, mismatched PE headers, or API monitoring rather than parent-child hierarchy alone.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.