CS0-003 Security Operations Practice Question
During a threat hunting exercise, an analyst uses osquery to query process events on endpoints. They discover a process named 'svchost.exe' running under a user account with parent process 'cmd.exe'. Which of the following describes this observation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Potential LOLBin abuse with anomalous parent-child relationship
svchost.exe should normally run under SYSTEM or NETWORK SERVICE with 'services.exe' as parent. A user-level svchost.exe with cmd.exe parent indicates a potential LOLBin misuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Normal behavior for Windows services
Why it's wrong here
While svchost.exe is a legitimate Windows system process used to host service DLLs, it normally executes under system accounts like SYSTEM, LocalService, or NetworkService. It is highly anomalous for it to be spawned by a user-controlled command interpreter like cmd.exe or to run under a standard user's security context. This deviation from the baseline strongly indicates malicious activity rather than standard operating system behavior.
- ✗
Evidence of a DLL injection attack
Why it's wrong here
DLL injection involves forcing an existing, running process to load a malicious dynamic-link library from disk. This technique manipulates the memory space of a target process but does not alter the process creation hierarchy or spawn a new process. Therefore, seeing cmd.exe act as the parent process to svchost.exe points to anomalous process creation rather than active memory injection.
- ✓
Potential LOLBin abuse with anomalous parent-child relationship
Why this is correct
Attackers frequently leverage legitimate binaries like svchost.exe as Living off the Land Binaries (LOLBins) to evade detection and bypass application whitelisting. In a standard Windows environment, services.exe is the exclusive parent process of svchost.exe. Observing cmd.exe spawning svchost.exe represents an anomalous parent-child relationship that strongly indicates an adversary attempting to masquerade malicious execution under a trusted system process name.
- ✗
Indicative of a process hollowing attack
Why it's wrong here
Process hollowing is an evasion technique where an attacker spawns a legitimate process in a suspended state, unmaps its memory, and replaces it with malicious payload code. While svchost.exe is a common target for hollowing, the detection of an anomalous parent-child relationship (such as cmd.exe spawning svchost.exe) is a distinct telemetry indicator of improper process creation. Process hollowing itself is typically identified through memory analysis, mismatched PE headers, or API monitoring rather than parent-child hierarchy alone.
Go deeper
Related to this question
Learn chapter
OSINT Sources for Threat Intelligence
Key term
Threat hunting
Threat hunting is a proactive cybersecurity practice where analysts actively search networks, endpoints, and logs for hidden threats that have evaded automated security tools.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.