CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard
A security analyst investigating a compromised endpoint finds that a legitimate, digitally signed system process (svchost.exe) has an unusually large memory footprint and is making outbound connections to an unfamiliar IP address, but no new files were written to disk. Which technique most likely explains this behavior?
- ADLL sideloading
- BLogic bomb execution
- CMemory (process) injection
- DRootkit installation
Show answer & explanationAnswer & explanation
Correct answer: C. Memory (process) injection
Memory injection (process injection) allows malicious code to run within the memory space of a legitimate, trusted process such as svchost.exe without writing new malicious files to disk, helping the attacker evade file-based detection while inheriting the trusted process's privileges and network activity.
Why the other options are wrong
- A. DLL sideloading involves tricking an application into loading a malicious DLL file from disk, which would typically leave a new file artifact.
- B. A logic bomb is dormant code triggered by a condition/event, not an explanation for a live process's memory and network anomalies.
- D. A rootkit typically involves kernel-level hooking and hiding, not necessarily explained solely by a single process's memory anomaly.
Memory (Process) Injection
A technique where malicious code is injected into and executed within the memory space of a legitimate running process, avoiding disk-based detection.
- No new malicious file typically written to disk
- Inherits the trusted process's privileges/identity
- Common techniques include DLL injection, process hollowing, and reflective DLL loading
Memory trick: Inject the poison straight into a trusted host's bloodstream, no footprints left.