Identifying Fileless Malware via PowerShell Execution

Answer Correct answer: C — The use of PowerShell with execution bypass and hidden window flags triggers an alert for fileless malware execution.

A security analyst is reviewing an IDS alert and sees the following: C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe -noP -exe byPass -nonI -wind hidden -no1 -c dir;findstr /s maldinuv %USERPROFILE%\\*.lnk > %USERPROFILE%\Documents\iijlqe.ps1;%USERPROFILE%\Documents\iijlqe.psi;exit Which of the following triggered the IDS alert?

  1. Bluesnarfing attack
  2. URL redirection attack
  3. Fileless malware execution Correct Answer
  4. Macro-based denial of service

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to recognize PowerShell abuse patterns (bypassing restrictions) as indicators of fileless malware rather than traditional network or application attacks.

This question analyzes a PowerShell command line containing execution bypass flags to determine the specific attack type. The correct identification is fileless malware execution, leveraging legitimate system tools for malicious purposes.

Learners often miss the significance of 'ExecutionPolicy Bypass' and focus on the directory listing aspect, potentially misidentifying it as simple reconnaissance or a different type of malware.

Community Discussion (4 comments)

Hs1208 👍 6 Selected: C
Fileless malware often uses legitimate system tools, such as PowerShell, to run malicious code directly in memory without dropping traditional executable files on disk. In this case, the command includes a PowerShell script that is being executed without the need for a separate executable file, making it characteristic of a fileless attack.
LayinCable 👍 3 Selected: C
It's 'C,' and here's why: A- Bluesnarfing is a bluetooth ONLY attack. Obviously, there's nothing about bluetooth in the question. B- URL Redirection is exactly what it sounds like, redirecting a URL to one that a malicious attacker wants the victim to go to. There's no URL's in the question. D- Macro-based denial of service. Macro is a programming language, and the input above is not a programming language input.
glenndexter 👍 2 Selected: C
dir: It lists the contents of the current directory. findstr /s maldinuv %USERPROFILE%\\.lnk: It searches for files with the name "maldinuv" in the shortcut files (.lnk) located in the user's profile directory. It redirects the output of the findstr command to a file named iijlqe.ps1 located in the user's Documents folder. It then tries to execute a file named iijlqe.psi, which seems to be a typo or an attempt to obfuscate the filename. The command then exits the PowerShell session.
1403ad2 👍 2 Selected: C
I think C. Fileless malware execution because other three have nothing to do with files def not DoS or A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The command line explicitly uses powershell.exe with critical arguments like -exe byPass (ExecutionPolicy Bypass) and -wind hidden (WindowStyle Hidden). These are hallmarks of fileless malware, which executes code directly in memory using trusted system utilities like PowerShell to evade signature-based detection. The script attempts to search for specific files and redirect output, operating without dropping a traditional executable payload on disk.

Why the Other Options Are Wrong

Bluesnarfing (A) targets Bluetooth vulnerabilities, which is unrelated to Windows PowerShell. URL redirection (B) involves web traffic manipulation, not local command-line execution. Macro-based denial of service (D) typically refers to Office automation scripts causing crashes, whereas this command is performing active reconnaissance and persistence mechanisms typical of advanced persistent threats (APTs).

Community Comment Notes

Community consensus strongly supports C. As user Hs1208 noted, "Fileless malware often uses legitimate system tools, such as PowerShell, to run malicious code directly in memory." User LayinCable correctly eliminated other options by pointing out the absence of Bluetooth or URLs. User glenndexter analyzed the specific commands (dir, findstr) as part of the malicious workflow.

Official Reference

Exam Strategy

When you see PowerShell commands with flags like -NonInteractive, -NoProfile, or -ExecutionPolicy Bypass, immediately consider fileless malware. Memorize these common evasion techniques to quickly identify them in exam scenarios.

Frequently Asked Questions

Why is this not a macro-based DoS?

Macros are associated with Office documents (VBA). This is a direct PowerShell CLI invocation, characteristic of fileless malware, not a document macro crash.

What does -exe byPass do?

It sets the ExecutionPolicy to 'Bypass', allowing scripts to run without warnings or prompts, a key tactic for fileless attacks to avoid triggering security alerts.

Related Analysis

← Back to SY0-601 Study Guide