CompTIA CySA+ (CS0-003)Security OperationsHard

Windows Security Event Log Event ID 4688 shows the following process creation entry on a user workstation: `New Process Name: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe` `Creator Process Name: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE` `Process Command Line: powershell.exe -nop -w hidden -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQA...` Which of the following BEST explains this event?

  1. AA scheduled task created by Group Policy for patch management
  2. BA malicious macro spawning an obfuscated, fileless PowerShell payload
  3. CA print spooler service exploit unrelated to Office
  4. DA legitimate Word mail-merge macro generating a report
Show answer & explanation

Correct answer: B. A malicious macro spawning an obfuscated, fileless PowerShell payload

Microsoft Word (WINWORD.EXE) spawning powershell.exe as a child process, using -nop (no profile), -w hidden (hidden window), and -enc (Base64-encoded command), is a strong indicator of a malicious macro executing an obfuscated, fileless PowerShell payload — a common technique to evade static file-based detection.

Why the other options are wrong

  • A. Group Policy scheduled tasks would not originate from WINWORD.EXE as the parent process.
  • C. Print spooler exploits involve spoolsv.exe, not Word spawning PowerShell.
  • D. Legitimate mail-merge operations do not spawn hidden, encoded PowerShell processes.

Fileless Malware via Office Macro

An attack technique where a malicious Office document macro spawns PowerShell with encoded/hidden flags to execute payloads in memory, avoiding disk-based detection.

  • Office app (WINWORD.EXE/EXCEL.EXE) as parent process of powershell.exe is suspicious
  • -enc, -nop, -w hidden flags indicate obfuscation and stealth
  • Event ID 4688 logs process creation with command-line auditing enabled

Memory trick: A document that secretly whispers hidden PowerShell commands.

More Security Operations questions