Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

A threat hunter is reviewing Sysmon logs from a Windows workstation that is suspected of being compromised. The hunter sees a process named 'svchost.exe' with a parent process of 'services.exe', but its image path is 'C:\Users\Public\svchost.exe' and it has an active network connection to an external IP address on port 443. Which two indicators should the hunter flag as highly suspicious in this scenario? (Choose two.)

⚠ Common exam trap

The trap here is assuming that because svchost.exe is a legitimate process and often runs as SYSTEM, any instance is benign; the anomaly is the path and network behavior, not the name or parent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process has an active network connection on port 443.

The two suspicious indicators are the non-standard image path and the external network connection. Legitimate svchost.exe runs from System32, so an instance in C:\Users\Public indicates masquerading. The external connection on port 443 suggests command-and-control or data exfiltration. Together, they strongly point to a compromised host, while the parent process and process name are normal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process name is svchost.exe.

    Why it's wrong here

    svchost.exe is a legitimate Windows process that hosts multiple services. Its presence alone is not suspicious. The hunter should focus on anomalies such as the image path and network behavior, not the process name itself. Flagging the name would generate false positives across nearly all Windows systems.

  • ✗

    The process is running under the SYSTEM account.

    Why it's wrong here

    Many legitimate svchost.exe instances run as SYSTEM. This is normal behavior for service hosting. In this scenario, the suspicious elements are the non-standard path and the external connection, not the user context. Therefore, the account under which it runs is not a reliable indicator of compromise here.

  • ✓

    The process has an active network connection on port 443.

    Why this is correct

    While svchost.exe can make network connections, an instance running from an unusual path making an external connection on port 443 is highly suspicious. Attackers commonly use HTTPS for command-and-control to blend with normal traffic. Combined with the anomalous path, this network activity strongly suggests malicious behavior and should be flagged.

  • ✗

    The parent process is services.exe.

    Why it's wrong here

    In a normal Windows environment, svchost.exe instances are launched by services.exe. This parent-child relationship is expected and not suspicious. The anomaly lies in the image path and network connection, not the parent. Therefore, this is a benign indicator and should not be flagged as suspicious in this context.

  • ✓

    The image path is C:\Users\Public\svchost.exe.

    Why this is correct

    Legitimate svchost.exe resides in C:\Windows\System32. An instance running from C:\Users\Public is a classic masquerading technique. Attackers often place malicious executables in user-writable directories with legitimate-sounding names to evade detection. This path deviation is a strong indicator of compromise and should be flagged.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.