SY0-701 exam dumps

SY0-701 practice question 489 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 489

Single answerExecution

A security analyst is reviewing alerts from several Windows endpoints after a user opened a malicious email attachment. The EDR shows the following sequence on one workstation: WINWORD.EXE spawned powershell.exe, which then launched a Base64-encoded command that downloaded additional content from an external site and created a scheduled task for persistence. Which stage of the cyber kill chain is most directly represented by the point where PowerShell runs the attacker-controlled command on the host?

  1. A

    Delivery

  2. B

    Exploitation

  3. C

    Execution

  4. D

    Installation

Show answer and explanation

Correct answer: C

Explanation

The best answer is Execution. In practical incident response, analysts often distinguish between how the attacker got code onto the system and when that code actually ran. In this scenario, the phishing attachment represents delivery, the user opening it may contribute to exploitation, the PowerShell process running the encoded payload is execution, and the scheduled task indicates follow-on installation or persistence activity. This aligns with common security operations practices and ATT&CK-style detection logic, where PowerShell misuse is often categorized under command and script interpreter activity. Security teams commonly validate this stage by reviewing EDR process trees, command-line arguments, script block logging, and PowerShell logs. Best practices from Microsoft and industry detection guidance emphasize monitoring Office applications spawning script interpreters, encoded PowerShell commands, and subsequent persistence creation as strong indicators of malicious execution.

  • A. Incorrect.

    Delivery is the stage in which the attacker transmits the malicious payload to the target, such as sending the phishing email with the attachment. In this scenario, the email attachment arriving in the user's mailbox is delivery, not the point where PowerShell actually runs the command.

  • B. Incorrect.

    Exploitation is the stage where a vulnerability or user action is leveraged to trigger malicious code, such as convincing the user to open the attachment or abusing an application to gain code execution. Some candidates choose this because the attachment led to compromise, but the question specifically asks about the moment the attacker-controlled command is run on the host.

  • C. Correct.

    Execution is correct because it refers to the malicious code actually running on the victim system. Here, PowerShell launches and runs an encoded attacker-controlled command, which is a classic example of execution. In modern attack analysis, scripting engines such as PowerShell, cmd.exe, wscript.exe, and rundll32 are commonly monitored because they are frequently used to execute payloads after initial access.

  • D. Incorrect.

    Installation refers to placing malware or persistence mechanisms on the system, such as dropping files, registering services, or creating scheduled tasks. The scheduled task in the scenario is an example of installation or persistence-related activity, but it occurs after the malicious command has already executed.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam