Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security analyst is investigating a suspected malware infection on a Windows endpoint. During host-based analysis, the analyst discovers a new process running with administrator privileges that is not digitally signed and is located in a highly unusual directory, 'C:\ProgramData\Temp\svchost.exe'. What is the most immediate concern raised by this discovery?

  1. APotential rootkit installation
  2. BInsufficient user access control settings
  3. CMalware attempting to masquerade as a legitimate process
  4. DLegitimate system process misconfiguration
Show answer & explanation

Correct answer: C. Malware attempting to masquerade as a legitimate process

The 'svchost.exe' is a legitimate Windows process, but finding an unsigned executable with that name in a non-standard directory like 'C:\ProgramData\Temp\' is a classic indicator of malware attempting to blend in by masquerading as a legitimate system process. This is a common tactic to evade detection.

Why the other options are wrong

  • A. While a rootkit might be present, the immediate concern is the masquerading process itself, which is a key characteristic of many malware types, not exclusively rootkits.
  • B. While insufficient UAC could allow it to run with admin privileges, the discovery itself points to the malware's deception tactic, not just a permission issue.
  • D. Legitimate system processes like svchost.exe are typically digitally signed and located in system directories (e.g., C:\Windows\System32), not in a temporary data directory.

Process Masquerading

A technique used by malware to hide its presence by naming its executable or process after a legitimate system process, often placing it in an unusual directory, to evade detection.

  • Malware uses legitimate process names (e.g., svchost.exe, explorer.exe).
  • Executables are often unsigned or have invalid signatures.
  • Files are typically found in non-standard system directories.

Memory trick: Look for the fake ID, not just the face, in the wrong place.

More Security Monitoring questions