GCFA Practice Question: Identification of Malicious and Normal Activity
While reviewing a Windows host, you find a 4688 process creation event where the new process is C:\Windows\System32\svchost.exe but the parent process image is C:\Users\bob\AppData\Local\Temp\update.exe. The command line for svchost.exe contains -k netsvcs with no additional arguments. Which assessment is best supported?
⚠ Common exam trap
The trap here is judging svchost.exe by its path and command line alone, when the parent process image is the artifact that exposes injection or masquerading.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The parent process path indicates a likely masquerading or code-injection event that warrants memory analysis of svchost.exe.
A user Temp directory as the parent of svchost.exe contradicts the normal services.exe parent-child relationship and points to injection or a masquerading loader. The correct-looking command line is part of the deception. Memory acquisition and module inspection of the process will confirm whether the service host is hosting malicious code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The parent process path indicates a likely masquerading or code-injection event that warrants memory analysis of svchost.exe.
Why this is correct
The legitimate parent of svchost.exe is services.exe, so a user Temp directory parent is a strong indicator of process injection, hollowing, or a masquerading loader. The command line matches a valid service host invocation, which an attacker would copy to blend in. Capturing a memory image of the process and checking loaded modules and thread start addresses is the appropriate next step.
- ✗
The command line is malformed and shows svchost.exe was invoked without the required -k service group.
Why it's wrong here
The -k netsvcs argument is exactly the service group syntax used by legitimate svchost.exe invocations, so the command line is well formed. The issue is the parent, not the arguments. Focusing on the command line misses the anomaly that actually distinguishes this event from benign service hosting, which is the non-standard parent process path.
- ✗
The event is a false positive caused by Sysmon logging the wrong parent process for service hosts.
Why it's wrong here
Sysmon and the Windows 4688 event both capture the true parent process image and its PID. There is no known behavior where the parent is misattributed for svchost.exe. Dismissing the anomaly as a logging error risks overlooking real injection activity, so this interpretation is not supported by the evidence.
- ✗
This is normal behavior because svchost.exe is frequently launched from user directories during updates.
Why it's wrong here
Legitimate svchost.exe instances are always launched by services.exe from System32, never from a user profile directory. The parent path in the stem is a user Temp folder, which is where droppers and downloaders typically stage payloads. Claiming normal update behavior ignores both the parent path anomaly and the well-known parent-child relationship for svchost.exe.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.