Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security analyst is investigating a critical alert from the SIEM indicating 'Suspicious process execution from an unusual directory' on a Windows server. Further examination shows that a process named 'iexplore.exe' (Internet Explorer) was launched from the 'C:\Temp\' directory, and it is making outbound connections to a known malicious IP address. What type of host-based intrusion is this most likely an indicator of?

  1. ADrive-by download leading to malware execution
  2. BLegitimate software update
  3. CUser error in launching an application
  4. DOperating system corruption
Show answer & explanation

Correct answer: A. Drive-by download leading to malware execution

A legitimate process (iexplore.exe) running from an unusual directory (C:\Temp\) and connecting to a malicious IP is a strong indicator of a drive-by download where malware masquerades as a legitimate application to evade detection.

Why the other options are wrong

  • B. Legitimate software updates would typically launch from standard program directories, not 'C:\Temp\'.
  • C. While possible, a user error causing 'iexplore.exe' to run from 'C:\Temp\' and connect to a malicious IP is highly improbable and points to malicious activity.
  • D. Operating system corruption would likely manifest with more widespread system instability, not just a single process anomaly.

Masquerading Process

A masquerading process is a malicious program that disguises itself with the name of a legitimate system process or application to evade detection by security tools and users.

  • Often runs from unusual directories (e.g., temp folders, user profiles).
  • May have unusual parent processes.
  • Exhibits suspicious network connections or resource usage.
  • Requires verifying process path, digital signature, and parentage.

Memory trick: Process anomalies are like finding a 'ghost' in your computer's machine room.

More Security Monitoring questions