Courseiva
Security Operations →hardMultiple Choice

CAS-004 Security Operations Practice Question

A security engineer is implementing a new endpoint detection and response (EDR) solution. The engineer wants to detect process injection techniques where malware writes to the memory of a remote process and then creates a remote thread to execute its payload. Which of the following Windows API call sequences should the EDR monitor to detect this behavior?

⚠ Common exam trap

It's easy for candidates to confuse process injection with other malicious behaviors like file manipulation or registry persistence, which use entirely different API sets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread

Remote process injection via CreateRemoteThread requires allocating memory in the target process (VirtualAllocEx), writing the payload (WriteProcessMemory), and then creating a thread to execute it (CreateRemoteThread). The OpenProcess call obtains the necessary handle. Monitoring this API sequence helps EDR solutions detect a common malware technique. The other options describe file, registry, or network operations that are not related to process injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RegOpenKeyEx, RegSetValueEx, RegCloseKey

    Why it's wrong here

    These API calls are used to modify the Windows registry, such as setting persistence via Run keys. While registry modifications are common in malware, they do not represent process injection. The scenario specifically asks about writing to remote process memory and creating a remote thread, which this sequence does not cover.

  • ✓

    OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread

    Why this is correct

    This sequence is the classic remote process injection pattern: OpenProcess obtains a handle to the target process, VirtualAllocEx allocates memory in its address space, WriteProcessMemory writes the payload, and CreateRemoteThread starts execution. Monitoring these API calls in sequence is a reliable indicator of remote thread injection, commonly used by malware to execute code in another process.

  • ✗

    WSAStartup, socket, connect, send

    Why it's wrong here

    This sequence is typical for network communication using Winsock: initializing the library, creating a socket, connecting to a remote host, and sending data. It indicates network activity, not process injection. The question focuses on memory manipulation and thread creation, so these network APIs are irrelevant.

  • ✗

    CreateFile, ReadFile, WriteFile, CloseHandle

    Why it's wrong here

    This sequence describes basic file operations: opening a file, reading its contents, writing to a file, and closing the handle. It does not involve cross-process memory manipulation or thread creation, so it is not indicative of process injection. It might be used for file-based activities, but not for injecting code into another process.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.