Courseiva

GCIH Network and Log Investigations Practice Question

An analyst discovers a suspicious file named 'svchost.exe' running from a user's 'AppData' directory. Why is this highly suspicious?

⚠ Common exam trap

Candidates assume svchost.exe running from any folder is legitimate because it is a known Windows binary, ignoring the importance of execution path context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Legitimate svchost.exe resides in System32.

The legitimate svchost.exe process is a core Windows system component that resides in the System32 directory and is launched by the Service Control Manager. It is designed to host multiple Windows services. Attackers often rename their malicious binaries to 'svchost.exe' to blend in with legitimate processes, but they rarely place them in user-writable directories like AppData. Detecting this is a key indicator of malware masquerading as system processes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It is always a virus.

    Why it's wrong here

    While this is highly suspicious and likely malware, stating it is 'always a virus' is imprecise. It could also be a rootkit, a backdoor, or a legitimate tool being used maliciously. Incident handlers must remain objective and perform analysis rather than making broad, unqualified diagnostic claims.

  • ✗

    Svchost must always run as SYSTEM.

    Why it's wrong here

    While the legitimate svchost process typically runs under the SYSTEM, LOCAL SERVICE, or NETWORK SERVICE accounts, the privilege level is not the primary indicator here. The critical red flag is the file location, as legitimate system binaries should never execute from a standard user's AppData directory.

  • ✓

    Legitimate svchost.exe resides in System32.

    Why this is correct

    The actual Windows svchost.exe binary is located in C:\Windows\System32. When an executable with the same name is found in a user's AppData directory, it is almost certainly a malicious attempt to hide in plain sight while maintaining persistence, which is a classic indicator of compromise.

  • ✗

    Svchost cannot be executed by users.

    Why it's wrong here

    Users can technically execute any file they have permissions for, regardless of the filename. The restriction is not about who can execute the file, but where the legitimate binary is stored. The suspicion arises from the path mismatch, not the execution capability of the user account.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.