Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

A forensic analyst is analyzing a Windows 10 memory image and finds a process named 'svchost.exe' with PID 4567. The process's parent is 'services.exe', but its executable path is C:\Users\Public\svchost.exe. The analyst also notices that the process has a network connection to an external IP on port 443. Which of the following is the most likely explanation for this finding?

⚠ Common exam trap

The trap here is trusting the process name and parent process, which can be spoofed, instead of verifying the executable path and network behavior, which are more reliable indicators of malicious activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process is a malicious executable masquerading as svchost.exe, using a legitimate parent process name and an external network connection for command and control.

A process named svchost.exe running from C:\Users\Public with a parent of services.exe and an external network connection is a classic sign of malware masquerading as a legitimate system process. The executable path is the key indicator, as legitimate svchost.exe runs from System32. The external connection suggests command and control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process is a legitimate svchost.exe that has been compromised via DLL hijacking, causing it to load a malicious DLL from the user directory.

    Why it's wrong here

    DLL hijacking typically involves loading a malicious DLL from a directory in the search order, but the executable path of svchost.exe itself would still be in System32. Here, the executable path is in C:\Users\Public, which indicates the main executable is malicious, not just a hijacked DLL. This explanation misidentifies the nature of the anomaly.

  • ✗

    The process is a legitimate svchost.exe that has been migrated to a user directory by Windows Update as part of a rollback operation.

    Why it's wrong here

    Windows Update does not migrate svchost.exe to user directories. Such a move would be highly abnormal and would likely break the system. This explanation is not supported by any known Windows behavior and ignores the clear signs of a masquerading malware process.

  • ✓

    The process is a malicious executable masquerading as svchost.exe, using a legitimate parent process name and an external network connection for command and control.

    Why this is correct

    Malware often names itself svchost.exe and places itself in user-writable directories like C:\Users\Public to appear legitimate. The parent being services.exe is likely spoofed or the malware was injected into a legitimate svchost process. The external connection on port 443 suggests command and control. This is a classic masquerading technique.

  • ✗

    The process is a legitimate svchost.exe instance that has been moved to a user directory by a system administrator for troubleshooting.

    Why it's wrong here

    Legitimate svchost.exe instances always reside in C:\Windows\System32 and are launched by services.exe from that location. Moving svchost.exe to a user directory would break service dependencies and is not a standard troubleshooting step. This explanation is highly unlikely and ignores the strong indicators of compromise.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.