CAS-004 Security Operations Practice Question
A security analyst is configuring an EDR solution to detect a specific fileless attack technique where malicious code is injected into the memory of a legitimate process. The analyst wants to trigger an alert when a process attempts to write to the memory of another process. Which Windows API function should the EDR monitor to detect this activity?
⚠ Common exam trap
It's easy for candidates to confuse memory allocation or thread creation APIs with the actual memory writing API, leading to monitoring the wrong function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WriteProcessMemory
The correct API to monitor for detecting memory writes to another process is WriteProcessMemory. This function is commonly used in process injection and fileless malware to place malicious code into a legitimate process's memory space. Monitoring it provides direct visibility into the injection attempt. Other APIs like CreateRemoteThread or VirtualAllocEx are related but do not directly capture the write operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NtCreateThreadEx
Why it's wrong here
NtCreateThreadEx is the native API for creating threads, similar to CreateRemoteThread. It is used for execution, not for writing memory. Monitoring it would help detect thread creation but not the memory writing step. The scenario asks for detecting memory writes, so this is not the correct API to monitor.
- ✗
CreateRemoteThread
Why it's wrong here
CreateRemoteThread is used to start a thread in another process, often for process injection, but it does not directly indicate memory writing. Monitoring this API alone may miss techniques that use other methods like queueing an APC or using SetThreadContext. The scenario specifically asks for detecting memory writes, so this is not the best choice.
- ✓
WriteProcessMemory
Why this is correct
WriteProcessMemory is the Windows API function used to write data to the memory of another process. Monitoring this API will directly detect attempts to inject code or modify memory in a remote process, which is a common step in fileless attacks. This aligns precisely with the requirement to detect memory writing to another process.
- ✗
VirtualAllocEx
Why it's wrong here
VirtualAllocEx allocates memory in another process, often a precursor to writing data, but it does not actually write the malicious code. While monitoring it can be useful, it may generate false positives from legitimate applications that allocate memory in other processes. The question specifically targets the write operation, so this is less direct.
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.