CAS-004 Security Operations Practice Question
A security engineer is implementing a new endpoint detection and response (EDR) solution. The engineer wants to detect process injection techniques where malware writes to the memory of a remote process and then creates a remote thread to execute its payload. Which of the following Windows API call sequences should the EDR monitor to detect this behavior?
⚠ Common exam trap
It's easy for candidates to confuse process injection with other malicious behaviors like file manipulation or registry persistence, which use entirely different API sets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
Remote process injection via CreateRemoteThread requires allocating memory in the target process (VirtualAllocEx), writing the payload (WriteProcessMemory), and then creating a thread to execute it (CreateRemoteThread). The OpenProcess call obtains the necessary handle. Monitoring this API sequence helps EDR solutions detect a common malware technique. The other options describe file, registry, or network operations that are not related to process injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RegOpenKeyEx, RegSetValueEx, RegCloseKey
Why it's wrong here
These API calls are used to modify the Windows registry, such as setting persistence via Run keys. While registry modifications are common in malware, they do not represent process injection. The scenario specifically asks about writing to remote process memory and creating a remote thread, which this sequence does not cover.
- ✓
OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
Why this is correct
This sequence is the classic remote process injection pattern: OpenProcess obtains a handle to the target process, VirtualAllocEx allocates memory in its address space, WriteProcessMemory writes the payload, and CreateRemoteThread starts execution. Monitoring these API calls in sequence is a reliable indicator of remote thread injection, commonly used by malware to execute code in another process.
- ✗
WSAStartup, socket, connect, send
Why it's wrong here
This sequence is typical for network communication using Winsock: initializing the library, creating a socket, connecting to a remote host, and sending data. It indicates network activity, not process injection. The question focuses on memory manipulation and thread creation, so these network APIs are irrelevant.
- ✗
CreateFile, ReadFile, WriteFile, CloseHandle
Why it's wrong here
This sequence describes basic file operations: opening a file, reading its contents, writing to a file, and closing the handle. It does not involve cross-process memory manipulation or thread creation, so it is not indicative of process injection. It might be used for file-based activities, but not for injecting code into another process.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.