Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunting exercise, an analyst discovers a suspicious PowerShell process that executed encoded commands and made outbound connections to an unknown IP address. The process tree shows it was spawned by a Microsoft Word instance. What is the most likely attack technique being observed?

⚠ Common exam trap

SC-200 often tests whether candidates can distinguish initial-access techniques (phishing/macro) from later-stage techniques (lateral movement, service execution) by reading the process tree carefully — the Word parent is the giveaway that this is initial execution, not post-exploitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing with malicious macro

A Microsoft Word process spawning PowerShell that then runs encoded commands and beacons to an unknown external IP is the textbook signature of a malicious macro. Office macros (VBA) are commonly used to launch PowerShell with -EncodedCommand, which base64-encodes the payload to evade string-based detection. The parent-child relationship (WINWORD.EXE → powershell.exe) combined with outbound C2 traffic confirms macro-based initial execution and command-and-control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service Execution

    Why it's wrong here

    Service Execution is incorrect because the observed behavior is a parent-child process relationship initiated from Microsoft Word, not from the Windows Service Control Manager (services.exe) or a service host. In a genuine service execution attack, a binary is registered as a service via sc.exe, CreateService, or similar APIs and then started, often running under a privileged service account. Here, no service registration, service start, or svchost.exe involvement is described; the process tree stems directly from an Office application.

  • ✓

    Phishing with malicious macro

    Why this is correct

    Phishing with malicious macro is correct because the suspicious chain—Microsoft Word spawning PowerShell with an encoded command line—is a classic indicator of a macro-enabled Office document used as an initial access vector. Attackers embed VBA macros that invoke PowerShell via a WMI CreateProcess or direct CreateProcess call, often using -EncodedCommand or -EncodedArguments to hide the payload from command-line logging and initial inspection. This aligns with MITRE ATT&CK techniques T1566.001 (Spearphishing Attachment) and T1204.002 (User Execution: Malicious File), where the macro acts as the execution trigger and PowerShell serves as the download cradle or in-memory loader.

  • ✗

    Execution via Rundll32

    Why it's wrong here

    Execution via Rundll32 is incorrect because the described process lineage involves Word directly spawning PowerShell, with no mention of rundll32.exe appearing anywhere in the chain. A rundll32-based execution would typically show rundll32.exe invoking an exported function from a DLL, such as a JavaScript or VBScript stub (e.g., rundll32.exe javascript:"\..\mshtml,RunHTMLApplication") or a malicious DLL, and rundll32.exe would be the immediate parent of any subsequent payload. Since the parent is Winword.exe and the child is powershell.exe, this option does not match the observed execution path.

  • ✗

    Lateral Movement via WMI

    Why it's wrong here

    Lateral Movement via WMI is incorrect because the evidence describes local process execution from within Word, not remote orchestration across hosts. WMI lateral movement (e.g., using Win32_Process.Create to launch a process on a remote machine) would manifest as an inbound or outbound WMI connection, typically with wmiprvse.exe as the hosting process and a remote target computer name in the logs. Here, there are no remote connections, no WMI activity, and no indication that any other host was involved; the attack remains a single-host phishing execution chain.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.