Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security analyst is investigating a critical alert from the SIEM indicating 'Suspicious process execution from an unusual directory' on a Windows server. Further examination shows that a process named 'iexplore.exe' (Internet Explorer) was launched from the 'C:\Temp\' directory, and it is making outbound connections to a known malicious IP address. What type of host-based intrusion is this most likely an indicator of?
- ADrive-by download leading to malware execution
- BLegitimate software update
- CUser error in launching an application
- DOperating system corruption
Show answer & explanationAnswer & explanation
Correct answer: A. Drive-by download leading to malware execution
A legitimate process (iexplore.exe) running from an unusual directory (C:\Temp\) and connecting to a malicious IP is a strong indicator of a drive-by download where malware masquerades as a legitimate application to evade detection.
Why the other options are wrong
- B. Legitimate software updates would typically launch from standard program directories, not 'C:\Temp\'.
- C. While possible, a user error causing 'iexplore.exe' to run from 'C:\Temp\' and connect to a malicious IP is highly improbable and points to malicious activity.
- D. Operating system corruption would likely manifest with more widespread system instability, not just a single process anomaly.
Masquerading Process
A masquerading process is a malicious program that disguises itself with the name of a legitimate system process or application to evade detection by security tools and users.
- Often runs from unusual directories (e.g., temp folders, user profiles).
- May have unusual parent processes.
- Exhibits suspicious network connections or resource usage.
- Requires verifying process path, digital signature, and parentage.
Memory trick: Process anomalies are like finding a 'ghost' in your computer's machine room.