Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

Exhibit

C:\Windows\System32\svchost.exe -k netsvcs -p
Parent: C:\Windows\System32\services.exe
User: NT AUTHORITY\SYSTEM
Network: 192.168.1.5:49152 -> 45.33.22.11:443
State: ESTABLISHED

Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?

⚠ Common exam trap

Examinees often assume processes named svchost.exe are automatically safe even when running on a domain controller with anomalous network destinations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process is establishing an outbound connection to an external IP address.

While svchost.exe is a legitimate Windows service host, the network connection originating from a domain controller to an external IP address is highly suspicious. Legitimate domain controller service traffic should be directed towards internal domain members or approved update servers. This specific pattern, combined with the process context, indicates potential lateral movement or data exfiltration attempts using a masqueraded system process to bypass basic security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process is running as NT AUTHORITY\SYSTEM.

    Why it's wrong here

    Running as SYSTEM is standard behavior for svchost.exe, which manages essential operating system services. Relying solely on the user context is insufficient for detecting malicious activity, as legitimate system services frequently operate under high-privilege accounts to perform administrative tasks within the Windows environment.

  • ✗

    The parent process is services.exe.

    Why it's wrong here

    The services.exe binary is the legitimate parent for svchost.exe processes in Windows. Observing this parent-child relationship is expected behavior and does not provide evidence of malicious activity. Analysts must look for deviations in network destination or process arguments rather than standard system hierarchy structures.

  • ✓

    The process is establishing an outbound connection to an external IP address.

    Why this is correct

    Domain controllers should have strictly controlled outbound traffic profiles. An established connection to an arbitrary external IP address from a core infrastructure process like svchost is a classic indicator of compromise, suggesting the system is acting as a pivot or is participating in a command-and-control communication channel.

  • ✗

    The process is using a high-numbered ephemeral port.

    Why it's wrong here

    High-numbered ephemeral ports are a standard feature of TCP/IP communication for any client-side connection. Their use is not inherently suspicious and occurs during routine legitimate network operations. Focusing on the ephemeral port ignores the critical context of the destination IP, which is the true indicator here.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.